Table of contents
I. General information on data protection
II. Privacy policy website
III. Information for applicants
IV. Information for business partners
I. General information on data protection
I.1 Reference to the responsible body:
DOSTOFARM GmbH
Hansacker 24
26655 Westerstede
We attach particular importance to the protection of your personal data. Your personal data is processed in accordance with data protection regulations, in particular the European General Data Protection Regulation (EU GDPR) and the German Federal Data Protection Act (BDSG-new).
The following information provides an overview of the type, scope and purpose of the collection, processing and transmission of personal data as well as the security measures used to protect this data.
Personal data is individual information about the personal or factual circumstances of an identified or identifiable natural person, such as your name, address, telephone number, date of birth, email address and IP address.
I.2 Legal bases for the processing of personal data
- Insofar as we obtain the consent of the data subject for the processing of personal data, Art. 6 para. 1 lit. a EU GDPR serves as the legal basis. You can revoke your consent to this processing at any time for the future in accordance with Art. 7 para. 3 EU GDPR.
- Art. 6 para. 1 lit. b EU GDPR serves as the legal basis for the processing of personal data required to fulfill a contract or to carry out pre-contractual measures.
- Insofar as the processing of personal data is necessary to fulfill a legal obligation to which our company is subject, Art. 6 para. 1 lit. c EU GDPR serves as the legal basis.
- If processing is necessary for the purposes of the legitimate interests pursued by our company or by a third party and such interests are not overridden by the interests or fundamental rights and freedoms of the data subject, the legal basis for processing is Art. 6(1)(f) EU GDPR. In this case, you have a right to object in accordance with Art. 21 EU GDPR.
-
I.3 Data erasure and storage duration
Personal data will be deleted as soon as the purpose of storage no longer applies. Data may also be stored if this is provided for by statutory retention obligations to which our company is subject (e.g. retention periods of up to 10 years under accounting and tax law in accordance with the German Fiscal Code (AO) and German Commercial Code (HGB)).
I.4 Your rights
Upon written request, we will inform you in accordance with Art. 15 EU GDPR in accordance with our legal obligation under Art. 12 EU GDPR whether and which of your personal data is processed or stored by us. Furthermore, you have the right to rectification of inaccurate data in accordance with Art. 16 EU GDPR, data portability in accordance with Art. 20 EU GDPR, blocking and erasure of your personal data in accordance with Art. 17 EU GDPR – provided there are no legal obligations to retain data – and the right to restriction of processing in accordance with Art. 18 EU GDPR. In addition, you have the right to contact the competent supervisory authority in accordance with Art. 77 EU GDPR.
IN ADDITION, YOU HAVE THE RIGHT TO OBJECT PURSUANT TO ART. 21 EU GDPR, INSOFAR AS THE PROCESSING RELATES TO LEGITIMATE INTERESTS PURSUANT TO ART. 6 ABS. 1 LIT. F EU GDPR.
If you have given us your consent to process your data, you can of course withdraw this consent at any time for the future in accordance with Art. 7 (3) EU GDPR.
If you have any questions regarding the processing of your personal data, you can contact our data protection officer, who is also available to you in the event of requests for information, suggestions or complaints.
Data Protection Officer of DOSTOFARM GmbH
Hansacker 24
26655 Westerstede
E-mail: mail@dostofarm.de
I.5 Changes to our privacy policy
In order to ensure that our privacy policy always complies with current legal requirements, we reserve the right to make changes at any time. This also applies in the event that the privacy policy has to be adapted due to new or revised services, for example new services.
Status: 2022
II. privacy policy website
II.1 Provision of the website
Use of hosting service providers
Our website is hosted on servers of a hosting service provider located in the EU on the basis of order processing in accordance with Art. 28 EU GDPR. As part of its services, the hosting service provider may have access to personal data of our users, in particular to technical data that is generated as part of the technical communication between you and our website (e.g. server log files). They may not use this data for their own purposes. The use of a hosting service provider is based on our legitimate interests pursuant to Art. 6 para. 1 lit. f EU GDPR in the provision of infrastructure and platform services, computing capacity, e-mail dispatch and security services.
Server log files
When you visit our website or use its services, the device you use to access the site automatically transmits log data (connection data) to our server. The corresponding information consists of:
- Type and version of the browser you are using,
- Type and version of the operating system you are using,
- Referrer URL of the page from which you reached our website,
- Date and time of access to our website,
- Name of the subpages you have accessed,
- IP address of your computer system,
- Amount of data transferred in each case.
-
The data collected is used exclusively for statistical evaluations for the purpose of operation, security and optimization of the website. For security reasons, however, we reserve the right to check the log data retrospectively if there is a justified suspicion of unlawful use based on concrete evidence. The data will not be stored for longer than necessary for this purpose. This collection is based on our legitimate interests in accordance with Art. 6 para. 1 lit. f EU GDPR.
Cookies
We use so-called cookies in some areas of the website in order to recognize visitor preferences and to be able to design the website in an optimal and attractive way. This facilitates navigation and a high degree of user-friendliness of the website. The processing by cookies for the technical provision of the website constitutes a legitimate interest pursuant to Art. 6 para. 1 lit. f EU GDPR / § 25 para. 2 TDDDG. In addition, the legal basis is Art. 6 para. 1 lit. a EU GDPR or Section 25 para. 1 TDDDG if we require your consent for the use of cookies (e.g. for marketing or analysis purposes).
Cookies are technologies that your browser automatically creates and that are stored on your end device when you visit our website. Cookies do not cause any damage to your computer and do not contain viruses. Most of the cookies we use are deleted again at the end of the browser session (so-called session cookies). Other cookies remain on your computer and enable us to recognize your computer on your next visit (so-called persistent or cross-session cookies). Thanks to these files, it is possible, for example, to display information on the site that is specifically tailored to your interests.
You can set your browser so that it informs you about the placement of cookies. This makes the use of cookies transparent for you. If you completely exclude the use of cookies, you may not be able to use individual functions of this website.
Security of your data
We use technical and organizational security measures to adequately protect the data you provide against accidental or intentional manipulation, loss, destruction or access by unauthorized persons. We therefore use SSL encryption for the transmission of confidential content, such as inquiries that you send to us as the site operator. You can recognize an encrypted connection by the fact that the address line of the browser changes from “http://” to “https://” and by the lock symbol in your browser line. If SSL encryption is activated, the data you transmit to us cannot be read by third parties. Our security measures are developed in line with the state of the art.
II.2 Making contact
If you contact us (e.g. via contact form, e-mail, telephone, social media), your personal data will be stored and processed by us for the purpose of processing the inquiry and any associated follow-up questions in accordance with Art. 6 para. 1 lit. b EU GDPR (in the context of pre-contractual/contractual measures) or in accordance with Art. 6 para. 1 lit. f EU GDPR (general inquiries). We do not pass on this data without your consent.
The data you provide will remain with us until you ask us to delete it, object to its storage or the purpose for which it was stored no longer applies (i.e. after your request has been processed), provided that this does not conflict with any statutory retention obligations.
II.3 Registration
If you register on our website in order to order goods, services and information in our online portal, personal data will be collected. Registration enables access to services and content that are only available to registered users. If required, registered users have the option of changing or deleting the data provided during registration at any time. Your data may be passed on to shipping and payment service providers commissioned by us to process your order. Your data will not be passed on to third parties beyond this. The processing of your personal data is carried out on the basis of contract processing (in accordance with Art. 6 para. 1 lit. b EU GDPR). This data will be deleted in accordance with the statutory retention obligations.
II.4 Newsletter
If you register for our newsletter on our website, we will use the personal data you provide in this context exclusively for sending the newsletter.
The registration for our newsletter takes place in a so-called double opt-in procedure. This means that after registering, you will receive an e-mail asking you to confirm your registration. This confirmation is necessary to prevent registrations from other e-mail addresses. Subscriptions to the newsletter are logged in order to be able to prove the registration process in accordance with the legal requirements (consent pursuant to Art. 6 para. 1 lit. a EU GDPR). This includes storing the time of registration and confirmation as well as the IP address. Any data we receive from you and the logged information will not be passed on to third parties.
You can revoke your consent to the collection and storage of your data and its use for sending the newsletter at any time without giving reasons. You will find a link to unsubscribe from the newsletter at the end of each newsletter.
II.5 Analysis tools
The analysis measures listed below and used by us are carried out on the basis of Art. 6 para. 1 lit. a EU GDPR (consent). With the use of these analysis measures, we want to ensure a needs-based design and the continuous optimization of our website. By means of the analysis tools, we record the use of our website pseudonymously and evaluate it for the purpose of optimizing our offer.
You can revoke your consent to us at any time with effect for the future.
Google Analytics
This website uses functions of the web analysis service Google Analytics. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4 Ireland. Google Analytics uses so-called “cookies”. These are technologies that are stored on your computer and enable your use of the website to be analyzed. The user and event data is automatically deleted after 14 months.
IP anonymization
We have activated the IP anonymization function on this website. This means that your IP address will be shortened by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area before being transmitted to the USA. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there. Google uses this information for the purpose of evaluating your use of the website, compiling reports on website activity and providing other services relating to website activity and internet usage to us. The IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data.
Browser plugin / Prevention of data collection
You may refuse the use of cookies by selecting the appropriate settings on your browser, however please note that if you do this you may not be able to use the full functionality of this website. You can also prevent Google from collecting the data generated by the cookie and relating to your use of the website (including your IP address) and from processing this data by Google by downloading and installing the browser plug-in available under the following link: https://tools.google.com/dlpage/gaoptout?hl=de
You can find more information on how Google Analytics handles user data in Google’s privacy policy: https://support.google.com/analytics/answer/6004245?hl=de
Order data processing
We have concluded a contract with Google for commissioned data processing and fully implement the strict requirements of the German data protection authorities when using Google Analytics.
Meta (Facebook) Pixel
This website uses the visitor action pixel from Meta to measure conversions. The provider of this service is Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland. However, according to Meta, the data collected is also transferred to the USA and other third countries.
This allows the behavior of site visitors to be tracked after they have been redirected to the provider’s website by clicking on a meta ad. This allows the effectiveness of the meta ads to be evaluated for statistical and market research purposes and future advertising measures to be optimized.
The data collected is anonymous to us as the operator of this website; we cannot draw any conclusions about the identity of the user. However, the data is stored and processed by Meta so that a connection to the respective user profile is possible and Meta can use the data for its own advertising purposes in accordance with the Meta Data Usage Policy. This enables Meta to place advertisements on Meta pages and outside Meta. This use of the data cannot be influenced by us as the website operator.
The use of meta pixels is based on Art. 6 para. 1 lit. f EU GDPR. The website operator has a legitimate interest in effective advertising measures, including social media. A corresponding consent is requested for the processing of your data (e.g. consent to the storage of cookies). This processing is carried out exclusively on the basis of Art. 6 para. 1 lit. a EU GDPR; consent can be revoked at any time.
You can find further information on the protection of your privacy in Meta’s data protection information: https://de-de.facebook.com/about/privacy/
You can also deactivate the remarketing function “Custom Audiences” in the settings for advertisements at https://www.facebook.com/ads/preferences/?entry_product=ad_settings_screen or on the website of the European Interactive Digital Advertising Alliance: http://www.youronlinechoices.com/de/praferenzmanagement/.
II.6 Third-party content and services
On the basis of our legitimate interest in accordance with Art. 6 para. 1 lit. f EU GDPR, content, services and services from other providers that complement our offer are integrated within our online offer. By using the services mentioned below, we want to ensure a needs-based design and the continuous optimization of our website. If we request your consent for the use of these services, the legal basis is Art. 6 para. 1 lit. a EU GDPR.
YouTube
Videos from the YouTube platform are integrated on our website. YouTube is a service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4 Ireland. Like most websites, however, YouTube also uses cookies to collect information about visitors to its website. YouTube uses these, among other things, to collect video statistics, to prevent fraud and to improve user-friendliness.
Further information on data protection at YouTube can be found in their privacy policy at http://www.youtube.com/t/privacy_at_youtube. There you will also find further information on your rights and setting options to protect your privacy.
Google Tag Manager
Google Tag Manager is used on our website. Google Tag Manager is a solution from Google Ireland Limited, Gordon House, Barrow Street, Dublin 4 Ireland that allows us to manage website tags via an interface. The tool itself (which implements the tags) is a cookie-free domain that does not collect any personal data. The Google Tag Manager triggers other tags, which in turn may collect data. The Google Tag Manager does not access this data. If a deactivation has been made by the user at domain or cookie level, this remains in place for all tracking tags that are implemented with Google Tag Manager. The tags used are named separately below and can be individually edited by you in the privacy settings, for example by deactivating cookies for these elements. Further information: https://www.google.com/policies/privacy/.
Hotjar
We use Hotjar to better understand the needs of our users and to optimize the offer and experience on this website. Hotjar’s technology gives us a better understanding of our users’ experiences (e.g. how much time users spend on which pages, which links they click on, what they like and dislike, etc.) and helps us to tailor our offering to our users’ feedback. Hotjar works with cookies and other technologies to collect data about the behavior of our users and their end devices, in particular IP address of the device (only collected and stored in anonymized form during your website use), screen size, device type (Unique Device Identifiers), information about the browser used, location (country only), preferred language for displaying our website. Hotjar stores this information on our behalf in a pseudonymized user profile. Hotjar is contractually prohibited from selling the data collected on our behalf.
Further information on data protection at Hotjar can be found at https://www.hotjar.com/legal/policies/privacy/.
hCaptcha
To protect the contact form from unwanted, automated messages, we use the hCaptcha service from Intuition Machines, Inc. As soon as you click on the “Load Captcha” button, your IP address is transmitted to hCaptcha. This tool displays captchas – small tasks that are easy for humans to solve but difficult for machines. These captchas help us to identify spam. This service basically processes technical information about your use of our website, such as mouse movements, scroll positions, buttons pressed, touch events on touch displays and any movements of your device (e.g. if you use our website with a smartphone). In addition, hCaptcha collects the answers to the small tasks you are asked. This data is processed by hCaptcha exclusively on our behalf in order to protect our website from bots and spam. Your (non-personal) answers to the small tasks you are asked (e.g. recognizing certain objects in images) are also used by hCaptcha to train algorithms. The service is offered by Intuition Machines, Inc, 350 Alabama St, #10, San Francisco, CA 94110, USA. The service is used to ensure the availability of the website, to protect against bots and on the basis of our legitimate interests. You can find hCaptcha’s privacy policy at https://www.hcaptcha.com/privacy. For more information about hCaptcha and Intuition Machines’ privacy policy, please see the following links: www.hcaptcha.com and www.hcaptcha.com/privacy.
Payment procedure
We offer the following payment methods for efficient and secure payment options. Personal data is processed and stored by the payment service providers. This data may be passed on to credit agencies as part of an identity and credit check. Further information can be found in the payment service providers’ terms and conditions and data protection notices. We only receive information about the confirmation or negative information about the payment.
Mastercard: Payment services (technical connection of online payment methods); Service provider: Mastercard Europe SA, Chaussée de Tervuren 198A, B-1410 Waterloo, Belgium; Legal basis: Performance of contract and pre-contractual inquiries (Art. 6 para. 1 lit. b EU GDPR); Website: https://www.mastercard.de/de-de.html; Privacy Policy: https://www.mastercard.de/de-de/datenschutz.html.
PayPal: Payment services (technical connection of online payment methods) (e.g. PayPal, PayPal Plus, Braintree); Service provider: PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg; Legal basis: Contract fulfillment and pre-contractual inquiries (Art. 6 para. 1 lit. b EU GDPR); Website: https://www.paypal.com/de; Privacy Policy: https://www.paypal.com/de/webapps/mpp/ua/privacy-full.
Visa: Payment services (technical connection of online payment methods); Service provider: Visa Europe Services Inc, London Branch, 1 Sheldon Square, London W2 6TT, UK; Legal basis: Performance of contract and pre-contractual inquiries (Art. 6 para. 1 lit. b EU GDPR; Website: https://www.visa.de; Privacy Policy: https://www.visa.de/nutzungsbedingungen/visa-privacy-center.html; Basis for third country transfers: adequacy decision (UK).
American Express: Payment services (technical connection of online payment methods); Service provider: American Express Europe S.A., Theodor-Heuss-Allee 112, 60486 Frankfurt am Main, Germany; Legal basis: Contract fulfillment and pre-contractual inquiries (Art. 6 para. 1 lit. b EU GDPR); Website: https://www.americanexpress.com/de/; Privacy Policy: https://www.americanexpress.com/de-de/firma/legal/datenschutz-center/online-datenschutzerklarung/.
SOFORT Banking: Payment services (technical connection of online payment methods); Service provider: This payment service, which was developed by Payment Network AG, is provided by various providers in different European countries, including Sofort GmbH, Theresienhöhe 12, 80339 Munich, Germany (hereinafter referred to as “Sofort GmbH”); Legal basis: Performance of contract and pre-contractual inquiries (Art. 6 para. 1 lit. b GDPR; Website: https://www.sofort.de/datenschutz.html; https://www.klarna.com/sofort/.
mollie
Regardless of which payment method you use, we use mollie B.V., Keizersgracht 121, NL-1015CJ Amsterdam, Netherlands, as our payment service provider for payment processing. Your payment data entered will be recorded and stored by mollie B.V. in accordance with Art. 6 para. 1 lit. b EU GDPR and only passed on to the companies involved in the payment process. For more information on data protection by mollie, please refer to mollie’s privacy policy: https://www.mollie.com/de/privacy.
You can object to the processing of your data at any time by sending a message to mollie. However, mollie may still be entitled to process your personal data if this is necessary for contractual payment processing. A revocation has no effect on the effectiveness of data processing operations that took place in the past.
Vimeo
Videos from the Vimeo platform are integrated on our website. Vimeo is operated by Vimeo, LLC, headquartered at 555 West 18th Street, New York, New York 10011, and provides the Google server with information about the use of our website. If you are logged in to Vimeo as a member, Vimeo assigns this information to your personal user account. You can prevent this assignment by logging out of your Vimeo user account before using our website and deleting the corresponding cookies from Vimeo. Further information on data processing and notes on data protection by Vimeo can be found at https://vimeo.com/privacy.
As Vimeo may use Google Analytics, we refer you to Google’s privacy policy(https://www.google.com/policies/privacy) and opt-out options for Google Analytics(http://tools.google.com/dlpage/gaoptout?hl=de).
Links to third party websites
On the basis of our legitimate interest, it may happen that links to other providers that supplement our offer are integrated within this online offer. When accessing websites linked to from this website, you may again be asked for information such as your name, IP address, browser properties, etc. This privacy policy does not regulate the collection, disclosure or handling of personal data by third parties. In this context, please note the special data protection declarations of the individual third-party providers and service providers whose links we include on our website.
II.7 Social media
We maintain publicly accessible online presences in social networks to communicate with the customers and interested parties active there and to present our services.
We would like to point out that user data may be processed outside the European Union. Furthermore, user data is generally processed for market research and advertising purposes. To the best of our knowledge, the providers also use cookies that store your usage behavior (also across different end devices). This allows targeted advertising to be displayed on the provider’s own platform and on third-party sites.
The processing of users’ personal data is based on our legitimate interests in effective user information and communication with users in accordance with Art. 6 para. 1 lit. f. EU GDPR. If the users are asked by the respective providers of the platforms for consent to data processing or if the user voluntarily sends information to our online presences, the legal basis for processing is Art. 6 para. 1 lit. a EU GDPR in conjunction with Art. 7 EU GDPR. If this information contains contract-relevant content, Art. 6 para. 1 lit. b EU GDPR serves as the legal basis.
For a detailed description of the respective processing and the opt-out options, we refer to the following linked information from the providers.
In the case of requests for information and the assertion of user rights, we would also like to point out that these can be asserted most effectively with the providers. Only the providers have access to the users’ data and can take appropriate measures and provide information directly. If you still need help, you can contact us.
- Facebook: Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland, Privacy Policy: https://www.facebook.com/about/privacy/Opt-Out: https://www.facebook.com/settings?tab=ads
- Instagram: Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland. Privacy Policy/Opt-Out: https://instagram.com/about/legal/privacy/.
- LinkedIn: LinkedIn Ireland Unlimited Company Wilton Place, Dublin 2, Ireland. Privacy policy: https://www.linkedin.com/legal/privacy-policy. Opt-Out: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.
- YouTube: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Privacy policy / opt-out: https://policies.google.com/privacy?hl=de&gl=de.
- Xing: XING AG, Dammtorstraße 29-32, 20354 Hamburg, Germany. Privacy policy / Opt-Out: https://privacy.xing.com/de/datenschutzerklaerung.
-
Facebook and Instagram (Meta)
If you interact with our social media pages on Facebook and Instagram (comment, like posts or send us a message), your data will be stored by us. These social networks are operated by Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland (hereinafter: Meta).
When operating a company profile on these channels, Meta and our company are joint controllers under data protection law in accordance with Art. 26 EU GDPR. Accordingly, we have concluded an agreement with Meta in which the respective obligations under the EU GDPR are regulated: https://www.facebook.com/legal/terms/page_controller_addendum.
Meta provides the profile operators with statistics and insights into the types of actions of our profile visitors (“Page Insights”). We have no influence on the collection of this data by Meta. According to Meta, this data is only provided to us in anonymized form so that the user cannot be identified from the information.
Personal data will be deleted as soon as the purpose of storage no longer applies. Data may also be stored if this is provided for by statutory retention obligations to which our company is subject.
Please note that when you use and access our Facebook and Instagram pages, your personal data will also be processed by the provider Meta. Meta is operated by Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland and the parent company based in the USA. Meta processes your data in addition to the above-mentioned processing for analysis and advertising purposes. To the best of our knowledge, Meta also uses cookies that store your usage behavior (also across different end devices). This enables Meta to display targeted advertising on its own platform and on third-party sites. Further information can be found in Facebook’s privacy policy: https://www.facebook.com/about/privacy/Instagram https://help.instagram.com/519522125107875. Facebook and Instagram also offer the option to object to certain data processing; information and opt-out options in this regard can be found at https://www.facebook.com/settings?tab=ads and https://www.instagram.com/accounts/privacy_and_security/. Please note that user data is also processed in the USA or other third countries in accordance with the Meta Privacy Policy. Meta only transfers user data to countries for which an adequacy decision has been issued by the European Commission in accordance with Art. 45 EU GDPR or on the basis of suitable guarantees in accordance with Art. 46 EU GDPR.
With regard to data processing via our Facebook and Instagram pages, you also have the option of asserting your data subject rights against Meta. Further information on this can be found in Meta’s privacy policy: https://www.facebook.com/about/privacy/.
II.8 Minors
Our online services are generally aimed at persons of legal age. Personal information of persons who have not yet reached the age of 16 may only be made available to us if the express consent of the parent or guardian has been obtained (Art. 8 EU GDPR). Processing without the consent of the parent or legal guardian is not permitted. We therefore reserve the right to delete all data relating to minors if we do not have the consent of a parent or guardian.
III. Information for applicants
III.1 Purpose and legal basis for collection and processing
Your data will be processed by us for the purpose of processing your application in accordance with Art. 88 EU GDPR in conjunction with Section 26 BDSG-new. If special categories of personal data within the meaning of Art. 9 para. 1 EU GDPR are voluntarily communicated as part of the application process, their processing is also carried out in accordance with Art. 9 para. 2 lit. b EU GDPR.
III.2 Recipients of your data
The recipients of your data are the departments involved in the HR process (including HR, managers and department heads) of the responsible department. Your data will be treated as strictly confidential and will not be passed on to third parties without your consent. A transfer to third countries or international organizations is not intended.
III.3 Storage of your data
Your application data will be deleted 180 days after the position has been filled. If you are also interested in future vacancies, we require your written consent to store your application documents for a longer period. You can revoke this consent at any time for the future in accordance with Art. 7 para. 3 EU GDPR. To do so, please send an e-mail with a corresponding note to the contact address given above.
IV. Information for business partners
IV.1 Purpose and legal basis for collection and processing
The primary purpose of data processing is to establish, implement and terminate the contractual relationship. The primary legal basis for this is Art. 6 para. 1 lit. b EU GDPR. Without this type of use of your data, it is not possible to carry out the business relationship between you and us.
We also process your data on the basis of Art. 6 para. 1 lit. f EU GDPR to protect our legitimate interests or those of third parties (e.g. public authorities). This may be necessary, for example, to maintain IT security and IT operations or for the purposes of corporate management, internal communication and other administrative purposes. You can object to this processing by stating specific reasons in accordance with Art. 21 EU GDPR.
We also process your data to fulfill legal obligations such as regulatory requirements, commercial and tax retention obligations or documentation obligations. The legal basis for this is Art. 6 para. 1 lit. c EU GDPR in conjunction with the nationally applicable laws.
In individual cases, we may also process your data on the basis of your separate consent given to us in accordance with Art. 6 (1) (a), 7 EU GDPR (e.g. when registering for our newsletter or publishing photo and video recordings). You are always free to decide whether you wish to give your consent. Once you have given your consent, you can withdraw it at any time with effect for the future. To do so, please use the link provided in the respective campaign or send your request to the contact address given above.
If we process your personal data for a purpose not mentioned above, we will inform you in advance.
IV.2 Recipients of your data
Within our company, only those persons receive your personal data who need it to fulfill our contractual and legal obligations. In addition, we sometimes use different service providers to fulfill these obligations, so that it may be necessary to transfer your personal data to other recipients outside the company, insofar as this is necessary to fulfill our contractual and legal obligations. These third parties may be, for example, authorities, financial institutions, suppliers, etc. In order to process your data technically, we sometimes use external service providers who are considered processors in accordance with Art. 28 EU GDPR. You can also request detailed information using the contact information above.
IV.3 Storage of your data
We only store your personal data for as long as it is required for the above-mentioned purposes. After termination of the contractual relationship, your personal data will be stored for as long as we are legally obliged to do so. This regularly results from legal obligations to provide evidence and retain data, which are regulated in the German Commercial Code and the German Fiscal Code, among others. The storage periods are up to ten years. In addition, personal data may be stored for the period during which claims can be asserted against us (statutory limitation period of three or up to thirty years).