Privacy
A. General information
The general information applies equally to data processing on our websites www.index-werke.de and ixshop.ixworld.com (additional information on this in B.), as well as to processing the personal data of our business partners and prospective customers (additional information on this in C.) and our applicants (additional information on this in D.).
1. Controller
The controller responsible for processing the personal data is:
INDEX-Werke GmbH & Co. KG Hahn & Tessky
Plochinger Straße 92
73730 Esslingen
Tel.: +49 711 3191-0
Email: info@index-werke.de
2. Data protection officer
You may reach our data protection officer at:
INDEX-Werke GmbH & Co. KG Hahn & Tessky
attn: Data Protection Officer INDEX-Werke
Plochinger Straße 92
D-73730 Esslingen
Tel.: +49 711 3191-0
Email: dsb@index-werke.de
3. Storage duration
The data we process will be stored for as long as is required for the respective purpose, while observing the statutory retention periods (e.g., according to the Commercial Code and the Tax Code, ten years for tax-relevant documents or six years for other business letters) (Art. 6(1)(c) GDPR). Data storage beyond the statutory retention periods is possible if you have given consent as per Art. 6(1)(a) GDPR or the purpose for the data processing is still valid.
4. Your rights
4.1 Right to information, rectification, erasure or restriction and portability
Pursuant to the prerequisites set out in Art. 15 to 20 GDPR, you have the right, free of charge, to receive information concerning the data we have stored about you, to have the data rectified, and to request the erasure or restriction of processing as well as the transfer of your personal data. In some cases, we may nevertheless not completely erase your data due to statutory storage obligations.
4.2 Right to lodge a complaint
You have a right to lodge a complaint with a supervisory authority. The supervisory authority with jurisdiction over us is the State Data Protection and Freedom of Information Officer for Baden-Württemberg, Königstraße 10a, 70173 Stuttgart.
4.3 Right to object
You may object at any time to the use of your data for purposes of direct marketing; you may also object any time to the use of your data (on the basis of Art. 6(1)(e) or (f) GDPR) for reasons arising from your particular situation, with future effect. Transmission costs according to the basic rates are the only cost incurred when asserting an objection.
4.4 Right to withdraw consent
Insofar as we process your data based on your consent, you may withdraw your consent at any time with effect for the future.
B. Supplementary information for visits to the website
B. Supplementary information for visits to the website
In addition to our general information (more on this in A.), we wish to inform you about how personal data is collected and for what purposes and on what legal basis it is processed on our websites www.index-werke.de and ixshop.ixworld.com. We also wish to inform you about whom we disclose the data to and for what purpose, as well as the setting options you have with respect to data processing.
1. Technical and functional availability of the websites
We process personal data in order to make our websites available to the greatest extent possible without technical and functional limitations and according to statutory requirements.
a. Logs
When you access our website, we store certain access data, for example the type of browser and the version, operating system used, the previously visited web page, access data and time of the server request, and the data query of the client (file name and URL). We use these data on an anonymized basis for statistical analysis without this data being associated with specific users.
The purpose of this data processing is to facilitate accessibility and the correct presentation of the websites on your device as well as for technical optimization. In this respect, we have a legitimate interest in this data. The basis for the processing is Art. 6(1)(f) GDPR as well as Section 15 of the Telemedia Act (TMG).
b. Consent Management Tool (CMT)
To obtain and document your consent to data processing, we have integrated a Consent Management Tool (CMT) on our website using various service providers.
When you access our website, you may provide respective consent declarations by means of the CMT for categories of data processing operations, which are stored by the CMT. With aid of the CMT, the next time you visit our website we will be able to track which data processing through which services you have consented to or not consented to. Thus, it is not necessary for you to once again make your selection every time you visit our website. For this purpose, the CMT stores a cookie, a small text file, on your computer. The cookies used are as follows:
Cookie name | Service | Cookie function | Function duration | Access by third-party providers |
cookieconsent_status | TYPO3 | Stores acceptance of the cookie notice | 1 yaer | |
fe_typo_user | TYPO3 | Standard session cookie of TYP03. FE login | ||
avsite_optin_functional | Cookiebanner | Settings of the cookie banner | 2 year | |
avsite_optin_statistic | Cookiebanner | Settings of the cookie banner | 2 year |
Of course, you may also modify your selection after the fact in the settings. You may open the settings at any time by going to [Cookie Banner].
We use the CMT so that you may consent to various data processing operations and withdraw consents that have been previously granted. We are obligated under the law to obtain and document your consent. The legal basis for the data processing by means of the CMT is Art. 6(1)(c) GDPR.
c. Required cookies
We use cookies, small text files that are stored on your computer, so that you may navigate and use all of the functions on the website without limitations. Without these cookies we cannot provide the services that you request from us. The legal basis for the data processing by means of the required cookies is Art. 6(1)(b) GDPR. These cookies are as follows:
- PREF: Stores the preferred page configuration of a visitor and playback settings such as autoplay, random playback, and player size; storage duration is 8 months; third parties do not have access to the processed data.
- fe_typo_user: Standard session cookie from TYPO3 for FE login; erased after the expiration of the session; third parties do not have access to the processed data.
2. Contact support
We collect personal data that you provide to us. This may involve data, for example, that you enter into a contact form or transmit to us in the course of establishing an initial contact. To the extent that certain input fields are labeled as "required information", with these fields we gather the data that is required to implement the requested measure. Of course, you may provide additional data to us if you wish.
This data is processed on the basis of Art. 6(1)(b) GDPR if this is required to implement a measure that you have requested. In all other cases, the processing is based on our legitimate interest in effectively handling the queries submitted to us (Art. 6(1)(f) GDPR).
3. Orders via the online shop
Customer accounts that are already created in our ERP system can register for a password-protected, free account in our online shop ixshop.ixworld.com. Once you have registered a user account, you may place orders via the online shop and view these along with your returns and wishlists. In addition, you can manage your personal information.
During registration, the data labeled as required information is collected (in particular your INDEX customer number, first and last name, and email address). You may modify this data at any time. With "required information" we collect the data that is necessary for the purpose of implementing the user relationship created through the registration – in particular for handling your orders (Art. 6(1)(b) GDPR). Of course, you may provide additional data to us if you wish. You may erase your personal user account at any time.
4. Advertising campaigns
We have a legitimate interest within the meaning of Art. 6(1)(f) GDPR in using your data for the purpose of direct marketing.
Insofar as you have provided your consent for this purpose (Art. 6(1)(a) GDPR), we will also use your data for the purpose of sending an email newsletter. The newsletter is technically configured so that we can track whether you have opened it. In the course of this, specific information on successful delivery, opening rates, click behavior, and unsubscribing is stored and processed. The information obtained is used to make the newsletter more attractive for you in the future. Your consent also applies to this tracking.
You may withdraw your consent to the distribution of the newsletter as well as the newsletter tracking at any time by clicking on the relevant link contained in every email newsletter or by sending a message to the contact set out above. In addition, you may object to the processing of your personal data for advertising purposes, effective for the future, in writing by fax, email, or telephone. Transmission costs according to the basic rates are the only cost incurred when asserting an objection. The lawfulness of any data processing operations already carried out will not be affected by this.
The newsletter is distributed by the service provider Inxmail GmbH, Wentzignerstr. 17, D-79106 Freiburg. The latter is bound by our instructions, obligated according to data protection law provisions, and may not use the data for another purpose.
5. Integrated services on our websites
5.1 Google services
To the extent that you have consented, our websites use services that are provided by Google Ireland Limited, Google Building Gordon House, 4 Barrow Street, Dublin, D04 E5W5, Ireland ("Google").
a. General information on the Google services, legal basis
Google processes personal data in order to provide the services. The legal basis for data processing by Google services is your consent, Art. 6(1)(a) GDPR.
Information collected by Google services may also be transmitted to and stored on a Google server in a third country, in particular, a server of the parent company of Google, Google LLC, with its registered office at 1600 Amphitheater Parkway, Mountain View, California, U.S. To ensure the security of this transmission to a third country, we have concluded standard data protection clauses with Google. Google ensures the observance of these data protection law agreements. Nevertheless, the transmission of personal data to the U.S. is associated with special risks for data subjects. Therefore, the integration and processing of data by Google services only takes place with your express consent. You may find more detailed information on transmission to a third country in section VII.
When you are logged into your Google account, Google can associate processed information with your account, depending on your account settings, and treat this information as personal data, cf. in particular https://www.google.de/policies/privacy/partners/. We do not have any knowledge about this type of collected data and its use.
You may find additional information about data processing on the part of Google at:
- https://policies.google.com/privacy ("Google Data Protection Statement")
- https://www.google.com/intl/de/policies/privacy/partners ("Data Use by Google When You Use Websites or Apps of our Partners")
- http://www.google.com/policies/technologies/ads ("Data Use for Advertising Purposes")
b. Google Analytics
Our websites use the Google Analytics service. Using cookies, small text files that are stored on your computer, this service undertakes a cross-website analysis of your surfing behavior. These cookies are as follows:
- _gid: Is applied to differentiate between visitors; the storage duration is 24 hours. Google has access to the processed data.
- NID: Is used in order to show Google ads in Google services for logged-out visitors; the storage duration is six months. Google has access to the processed data.
- _gat_UA-69558560-…: Contains campaign-related information for the visitor and can be used in combination with Google Ads; the storage duration is 90 days. Google has access to the processed data.
- 1P_JAR: Collects statistics for website use and measures conversions; the storage duration is one month. Google has access to the processed data.
- _ga: Is applied to differentiate between visitors; the storage duration is two years. Google has access to the processed data.
Google processes the collected data on our behalf in order to provide us with pseudonymous profiles of individual visitors and general statistics concerning the use of our website. We use the information in order to improve our website and to design the site to be more interesting for you as a visitor.
Our website also uses the function "Google Optimize" from Google Analytics. Google Optimize analyzes the use of different versions of our website ("A/B Tests") and thereby assists us in improving user-friendliness according to the behavior of our visitors to the website.
In addition, our websites use the Google Analytics “demographic characteristics”. By analyzing your surfing behavior, Google can make statistical observations on demographic characteristics and interests (age, gender, affinity categories, segments with target audiences who are ready to purchase) of the visitors to our websites. However, we are unable to associate this data with any particular person. We use the demographic information in order to improve our website and to design the site to be more interesting for you as a visitor. You may find additional information about data processing by means of the "demographic characteristics" of Google Analytics at: https://support.google.com/analytics/answer/2799357?hl=de.
IP anonymization is enabled on our websites so that your IP address is truncated prior to storage by Google Analytics. Only in exceptional cases will the full IP address be transmitted to a Google LLC server in the U.S. and truncated there. According to Google, the truncated IP address communicated by your browser as part of Google Analytics is not associated with any other data held by Google.
You may download and install a plug-in for the browser you use to disable Google Analytics on all websites by going to the following link: http://tools.google.com/dlpage/gaoptout?hl=de.
You may find further information on data processing by Google Analytics at: https://support.google.com/analytics/answer/6004245?hl=de%20.
c. Google Ads
Our website www.index-werke.de uses Google Ads in order to draw attention to our products and services in Google search results as well as on the websites of third parties.
We only want to place ads that are interesting for you. For this purpose, your surfing behavior on our website is analyzed by Google. For this so-called "re-marketing measure", cookies are stored on your device by Google. These cookies are as follows:
- IDE: Is used in order to show Google ads in Google services on websites that do not belong to Google; the storage duration is one year. Google has access to the processed data.
When you click on an ad placed for us by Google in the Google search results or on the website of a third party, cookies are stored on your device for the purpose of conversion tracking. These cookies have validity for a limited time. When you subsequently visit certain pages of our website, and provided the cookies have not yet expired, Google can recognize that you have clicked our ad and were forwarded on to our website. In this way, Google can provide us a statistical analysis on the effectiveness of our advertising measures. For the purpose of conversion tracking, these cookies are used:
- 1P_JAR: Collects statistics for website use and measures conversions; the storage duration is one month. Google may have access to the processed data.
You may enable or disable personalized advertising from Google by changing your advertising settings at this link: https://adssettings.google.com/anonymous?sig=ACi0TCjoT_RnPbIUe8IGa85dyA_5J4bol6TV5SM7jVOJycoeZaGP6BA8RWwSWmRUP0XRoURUu0XBV15kNZzQKE4cntIuJx15vg&hl=de. These settings will be stored in your Google account (if you are logged in) or in the browser (if you are not logged in). Alternatively, you have the option to install a plug-in for your browser to disable personalized advertising by going to this link: https://support.google.com/ads/answer/7395996?hl=de.
You may find additional information about the data processing and functionality of Google Ads at:
- https://ads.google.com/
- https://ads.google.com/intl/de_de/home/faq/gdpr/
- https://policies.google.com/technologies/ads
d. Google Maps
Our website www.index-werke.de uses Google Maps in order to visually display geographic information and to provide directions.
The embedding of Google Maps is linked to your settings in our Consent Management Tool. Thus, you are initially only shown a preview image on our website, without a connection to Google being established through this. It is not until you have enabled the map function in settings that a connection is established to Google. In this way, your IP address is transmitted to Google's servers and consequently, Google is informed that our website was visited with your IP address.
You have the option to disable the Google Maps service and in this way prevent the data transfer to Google by disabling JavaScript in your browser settings. However, we wish to note that in this case you will be unable to use the map display.
You may find further information on Google Maps: https://www.google.com/intl/de_de/help/terms_maps.html (terms of use for Google Maps).
e. YouTube
We have integrated videos of the Google service YouTube on our website www.index-werke.de, so that you may view these videos.
The embedding of YouTube is linked to your settings in our Consent Management Tool. Thus, you are initially only shown a preview image on our website, without a connection to Google being established through this. It is not until you have enabled the playback of videos in the settings that a connection is established to Google. In this way, your IP address is transmitted to Google's servers and consequently, Google is informed that our website was visited with your IP address. In addition, according to Google’s own information, the company can collect data on your user behavior by means of cookies, small text files that are stored on your computer. These cookies are as follows:
- YSC: Stores user input and associates these activities with the user; the cookie is stored for as long as the visitor has their browser open. Google has access to the processed data.
- VISITOR_INFO1_LIVE: Is used in order to show Google ads in Google services on websites that do not belong to Google; the storage duration is six months. Google has access to the processed data.
You also have the option to disable the YouTube videos, and in this way, prevent the data transfer to Google by disabling JavaScript in your browser settings. However, we wish to note that in this case you will be unable to use the video function.
You may find additional information about YouTube at: https://www.youtube.com/t/terms (terms of use for YouTube).
5.2 Facebook Pixel
Insofar as you have provided your consent, our website www.index-werke.de uses the function Facebook Pixel of Facebook Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland ("Facebook").
We can place ads on Facebook to draw attention to our products and services. You want you only to see our ads on Facebook if these are of interest to you. In order to determine whether our ad could be interesting for you, your surfing behavior is analyzed on our website with Facebook Pixel.
If one of our ads is displayed for you on Facebook and you click on the ad, you may be redirected to our website. In this case, Facebook can track by means of Pixel that you clicked on our ad and were redirected to our website. In this way, Facebook can provide us a statistical analysis on the effectiveness of our advertising measures (conversion tracking).
If you are logged into Facebook with your profile, Facebook can add the data collected to your user profile. In addition, Facebook can use the collected data for its own advertising purposes according to the Facebook data use policy.
The data collected by Facebook may also be transmitted to and stored on a Facebook server in a third country, in particular, a server of the parent company of Facebook, Facebook Inc., with its registered office at 1601 Willow Road Menlo Park, CA 94025, U.S. To ensure the security of this transmission to a third country, we have concluded standard data protection clauses with Facebook. Facebook ensures the observance of these data protection law agreements Nevertheless, the transmission of personal data to the U.S. is associated with special risks for data subjects. Therefore, the integration and processing of data by Facebook Pixel only takes place with your express consent. You may find more detailed information on transmission to a third country in section VII.
The legal basis for data processing by Facebook is your consent, Art. 6(1)(a) GDPR.
Users logged into Facebook can adjust the settings for advertising at: www.facebook.com/ads/preferences.
You may obtain additional information on data processing by Facebook as well as your respective rights and setting options to protect your privacy at: de-de.facebook.com/about/privacy/.
5.3 LeadLab
Insofar as you have provided your consent, our website www.index-werke.de uses the "LeadLab" service provided by WiredMinds GmbH, Lindenspürstraße 32, 70176 Stuttgart ("WiredMinds").
On our behalf, WiredMinds collects the IP address of a visitor with the aid of tracking pixels or web beacons. This address is then checked against a company database. It can thus be determined whether a visitor is employed in a certain company. If a visitor can be matched to a company, WiredMinds also analyzes the visiting behavior on our website. According to the information provided by WiredMinds, IP addresses of natural persons are excluded from further use (whitelist procedure). According to WiredMinds, there is no storage of the IP address in LeadLab.
The transmission and processing of your personal data by WiredMinds only takes place after you have provided consent. In this respect, the relevant legal basis is Art. 6(1)(a) GDPR.
You may find additional information about data protection at WiredMinds at:
5.4 MINQ
Insofar as you have provided your consent, our website www.index-werke.de uses the “MINQ” service provided by ADDVALUE GmbH, Ernst-Barlach-Straße 20, 36041 Fulda (“Addvalue”).
On our behalf, MINQ collects information on the visitors to our website using tracking scripts. The information collected is transmitted to Addvalue, where it is compiled, stored, and made available for the identification of website visitors. Based on the information, Addvalue ascertains whether a visitor is employed in a certain company. In this way, we can track which companies are interested in our products and services. According to Addvalue, the visit data of individual persons is not stored or processed.
The transmission and processing of your personal data by Addvalue only takes place after you have provided consent. In this respect, the relevant legal basis is Art. 6(1)(a) GDPR.
You have the option to disable MINQ and in this way, prevent the data transfer to Addvalue in that you disable JavaScript through your browser settings. However, we wish to note in this case that it is not possible to use our website without restrictions.
You may find additional information about data protection at Addvalue at:
5.5 Cloudflare
Insofar as you have provided your consent, our website www.index-werke.de uses the service of Cloudflare, which is provided by Cloudflare Germany GmbH, Rosental 7, 80331 Munich ("Cloudflare").
Cloudflare is a content delivery network that makes our website faster and more secure. With the aid of this service, on the one hand, our websites are made available for access on various servers around the entire world, by which the performance is improved. On the other hand, Cloudflare protects our websites from attacks by means of intermediary security services and firewalls. In order to facilitate this, Cloudflare processes the IP addresses of our visitors and creates logs about the use of our websites.
The information collected by Cloudflare may also be transmitted to and stored on a Cloudflare server in a third country, in particular, a server of the parent company of Cloudflare, Cloudflare Inc., with its registered office at 101 Townsend St., San Francisco, CA 94107, U.S. To ensure the security of this transmission to a third country, we have concluded standard data protection clauses with Cloudflare. Cloudflare ensures the observance of these data protection law agreements. Nevertheless, the transmission of personal data to the U.S. is associated with special risks for data subjects. Therefore, the integration and processing of data by Cloudflare only takes place with your express consent. You may find more detailed information on transmission to a third country in section VII.
The relevant legal basis for data processing by Cloudflare is your consent, Art. 6(1)(a) GDPR.
You may find additional information about the data processing and functionality of Cloudflare at:
- https://www.cloudflare.com/de-de/application/privacypolicy/?utm_referrer=https://www.cloudflare.com/de-de/gdpr/introduction/
- https://www.cloudflare.com/de-de/gdpr/introduction/
- https://support.cloudflare.com/hc/de/articles/205177068-Wie-funktioniert-Cloudflare-
6. Transmission of data collected on the websites to third parties
Your personal data is only transmitted to third parties in connection with our website insofar as data protection law allows for this, in particular, if you have consented to this transmission (Art. 6(1)(a) GDPR) or this is necessary for performance of a contract (Art. 6(1)(b) GDPR).
Categories of recipients of personal data that are not bound by instructions are: transport and logistics companies as well as providers of map, video, and analysis tools.
Categories of service providers bound by instructions and obligated pursuant to data protection law provisions that may not use the data for another purpose are: service providers for delivery of the newsletter and those managing website hosting.
7. Third country transmission
Our websites integrate the services of companies with registered offices in the U.S. or with affiliations in the U.S. If you consent to data processing by one of these service providers, it is possible that the U.S. authorities will gain unlimited access to the data processed about you. There is no legal avenue available for you to contest this in court. Specifically, these service providers are:
Third country transmission to www.index-werke.de
1. Services: Google Analytics
Provider: Google Ireland Limited, Dublin/Ireland
Parent company: Google LLC, Mountain View/U.S.
2. Services: Google Ads
Provider: Google Ireland Limited, Dublin/Ireland
Parent company: Google LLC, Mountain View/U.S.
3. Services: YouTube
Provider: Google Ireland Limited, Dublin/Ireland
Parent company: Google LLC, Mountain View/U.S.
4. Services: Google Maps
Provider: Google Ireland Limited, Dublin/Ireland
Parent company: Google LLC, Mountain View/U.S.
5. Services: Facebook Pixel
Provider: Facebook Ireland Limited, Dublin/Ireland
Parent company: Facebook Inc., CA/U.S.
6. Services: Cloudflare
Provider: Cloudflare Germany GmbH, Munich
Parent company: Cloudflare Inc., CA/U.S.
Third country transmission to www.ixshop.index-traub.com
1. Services: Google Analytics
Provider: Google Ireland Limited, Dublin/Ireland
Parent company: Google LLC, Mountain View/U.S.
It is possible that the companies or the respective parent companies and/or U.S. authorities will gain access to personal data that is processed for the purpose of making the services available.
The legal basis for this transmission of personal data to the U.S. was the certification of the companies or their parent companies according to the EU-U.S. Privacy Shield, which, however, was declared to be invalid by the European Court of Justice in July 2020. Transmission on the basis of the standard data protection clauses set out in Art. 46(2)(c) GDPR is not possible because it has to date not (yet) been possible to fulfill the high standards of the European Court of Justice and the data supervisory authorities for additional agreements with companies in the U.S. Negotiations are being conducted between the U.S. and the EU concerning a successor agreement to the Privacy Shield, but it is not foreseeable when these will be concluded.
As a result, although we conclude the standard data protection clauses with the companies, we only use the services mentioned with your prior, express consent and wish to explicitly note the following with regard to the risks of data transmission to one of the above-mentioned service providers:
Due to the authority of the U.S. secret services and the legal situation in the U.S., the governmental surveillance measures in the U.S. are disproportionate and, from the EU perspective, there is not an appropriate level of government protection for data. In particular, Sec. 702 of the American Foreign Intelligence Surveillance Act (FISA) does not provide any restrictions on surveillance measures of the secret services or any assurances for non-U.S. citizens. In addition, Presidential Policy Directive 28 (PPD-28) does not give data subjects any effective legal remedies against measures taken by U.S. authorities and does not provide any limitations with regard to ensuring proportionate measures. Moreover, U.S. authorities, based on the U.S. Cloud Act, can demand from a U.S. company the disclosure of all stored data, even if this data is located on servers within the EU.
8. Additional setting options
8.1 Disabling cookies
On our website, some of the previously described processing operations use cookies. Most browsers automatically accept cookies. If you do not wish to accept this, you can disable the storage of cookies on your hard drive in your browser settings. In addition, in your browser settings, you can at any time erase cookies that have been stored. However, it is possible that in this case, you will be unable to fully use all of the functions of our website.
8.2 Exercising your right to withdraw consent via the Consent Management Tool
On our websites, some of the previously described processing operations are only carried out with your consent. You may withdraw your consent to the implementation of these processing sequences at any time, effective for the future. It is possible that in this case you may be unable to use our services as before, until you have once again consented to the respective data processing. You may exercise your right to withdraw consent via our Consent Management Tool (CMT). In this manner, you may once again consent to the individual data processing operations on our websites.
C. Supplemental information for business partners and prospective customers
In addition to our general information (more on this in A.), we wish to inform you below how the personal data of our business partners and prospective customers is collected and for what purposes and on what legal basis it is processed. We also inform you about who receives the data of our business partners and prospective customers and for what purpose.
1. Purpose and legal basis for processing personal data of our business partners and prospective customers
We process personal data according to Art. 6(1)(b) GDPR that is required for complying with our obligations within the scope of initiating a contract and arising from the contractual relationships with our business partners, in particular for the purchase of products, supply of our products, correspondence, and for invoicing and payment. Included in this is in particular, the first name, last name, a valid email address, telephone number (landline and/or mobile cellular) and bank account.
We may process the personal data of our existing customers for the purpose of sending information about our services (e.g., product information, promotions or invitations to events). We have an associated, legitimate interest in this within the meaning of Art. 6(1)(f) GDPR. You may object to this processing at any time. Transmission costs according to the basic rates are the only cost incurred when asserting an objection.
2. Transmission of personal data of our business partners and prospective customers to third parties
Your personal data is only transmitted to third parties insofar as data protection law allows for this, in particular, if you have consented to this transmission (Art. 6(1)(a) GDPR) or this is necessary for performance of a contract (Art. 6(1)(b) GDPR).
D. Supplementary information for applicants
In addition to our general information (more on this in A.), we wish to inform you below how the personal data of our applicants is collected and for what purposes and on what legal basis it is processed. In addition, we provide information concerning when the applicant data is once again erased.
1. Purpose and legal basis for processing the personal data of our applicants
We store and process the personal data that you voluntarily communicate to us within the scope of the application process, such as, in particular, first and last name, address, email address, birth date, place of birth, profession, curriculum vitae, certificates, and special categories of personal data (for example, information about your religious beliefs or health data). In the course of the application process, additional data may accumulate that is relevant for the application, which will likewise be stored and processed. Your personal data will only be processed for the purpose of conducting the application process. In this respect, the legal basis for data processing is Section 26(1)(1) of the Federal Data Protection Act [Bundesdatenschutzgesetz (BDSG)]. In the event of a successful application process, the data will be applied to your personnel file for the purpose of implementing the employment relationship, Section 26(1)(1) BDSG.
2. Erasure of applicant data
If your application is not successful, your personal data will be erased no later than six months after the end of the application process unless processing your data is required for asserting, exercising, or defending legal claims (cf. Art. 17(3)(e) GDPR).
Your data will only be processed beyond the specific application process if you have also expressly consented to your data's continued storage in our database after the expiration of the respective application process so that we may potentially contact you at a later date if there are job vacancies. In the event that we no longer contact you, you may withdraw your consent at any time, effective for the future, via email or by telephone. Otherwise, your data will be erased after two years. If we contact you within this time period with respect to new positions, this time period commences once again with each such contact.