Privacy Policy
We are pleased that you have visited our website, www.schillinggroup.de, and are interested in our company.
The protection of your personal data—such as your date of birth, name, phone number, address, etc.—is very important to us.
The purpose of this Privacy Policy is to inform you about the processing of your personal data that we collect when you visit our website. Our data protection practices comply with the legal provisions of the EU General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG). The following Privacy Policy serves to fulfill the information obligations arising from the GDPR. These can be found, for example, in Articles 13 and 14 et seq. of the GDPR.
Person in charge
The controller within the meaning of Article 4(7) of the GDPR is the person who, alone or jointly with others, determines the purposes and means of the processing of personal data.
The controller for our website is:
C.ENTER GmbH & Co. KG
Eisenerzstr. 36
53819 Neunkirchen-Seelscheid
Germany
Email: info@cdotenter.de
Fax: +49 (0) 2247 9239 19
Contact information for the Data Protection Officer
We have appointed a data protection officer in accordance with Art. 37 of the GDPR. You can contact our data protection officer using the following contact information:
Patrick A. Scholz
Eisenerzstr. 36
53819 Neunkirchen-Seelscheid
Germany
Email: dsb@cdotenter.de
Website: http://www.schillinggroup.de/
Website hosting and log file generation
Every time you visit our website, our system automatically collects data and information about the device used to access the site (e.g., computer, mobile phone, tablet, etc.).
What personal data is collected, and to what extent is it processed?
(1) Information about the browser type and version used;
(2) The operating system of the device used to access the site;
(3) Hostname of the accessing computer;
(4) The IP address of the device used to access the site;
(5) Date and time of access;
(6) Websites and resources (images, files, other page content) accessed on our website;
(7) Websites from which the user’s system accessed our website (referrer tracking);
(8) Notification of whether the request was successful;
(9) Amount of data transferred
This data is stored in our system's log files. This data is not stored together with the personal data of any specific user, so individual site visitors cannot be identified.
Legal basis for the processing of personal data
Art. 6(1)(f) of the GDPR (legitimate interest). Our legitimate interest is to ensure that the purpose described below is achieved.
Purpose of data processing
The temporary (automated) storage of data is necessary for the website visit to proceed and to enable the website to be displayed. Personal data is also stored and processed to ensure that our website remains compatible for as many visitors as possible, as well as to combat misuse and resolve technical issues. To this end, it is necessary to log the technical data of the accessing computer so that we can respond as quickly as possible to display errors, attacks on our IT systems, and/or malfunctions in our website’s functionality. In addition, we use this data to optimize the website and to generally ensure the security of our IT systems.
Duration of storage
The aforementioned technical data will be deleted as soon as it is no longer needed to ensure the website’s compatibility for all visitors, but no later than 3 months after the website is accessed.
Right to object and request deletion
You may object to the processing of your data at any time in accordance with Article 21 of the GDPR and request the erasure of your data in accordance with Article 17 of the GDPR. You can find information about your rights and how to exercise them at the bottom of this Privacy Policy.
Special features of the website
Our website offers various features, and when you use them, we collect, process, and store personal data. Below, we explain what happens to this data:
Application Form
What personal data is collected, and to what extent is it processed?
The data you enter in the fields of the application form and any files you upload will be processed solely for the purpose described below.
Legal basis for the processing of personal data
The legal basis for the collection and processing of applicant data is Article 6(1)(b) (pre-contractual measures) and Article 88(1) of the GDPR in conjunction with Section 26 of the BDSG. To the extent that special categories of personal data are collected that are necessary to fulfill legal obligations under labor law, social security law, and social protection law pursuant to Article 9(2)(b) of the GDPR in conjunction with Section 26(3) of the BDSG, processing is carried out on this legal basis. To the extent that special categories of personal data are to be processed beyond this, we will obtain consent for this in accordance with Article 9(2)(a) of the GDPR.
Purpose of data processing
The purpose of processing your data is to review and process the application materials you have uploaded via the form.
Duration of storage
The data will be deleted as soon as the application has been processed and there is no longer a legitimate interest in storing the application data. Therefore, if an employment relationship is not established, your application documents will be deleted after 6 months at the latest.
Right to object and request deletion
You can find information about your rights and how to exercise them at the bottom of this privacy policy.
Requirement to Provide Personal Information
The information on the application form is not required by contract or by law, but it is necessary for submitting and processing your application. If you do not fill out the required fields, or do not fill them out completely, your application cannot be submitted or processed.
Contact form(s)
What personal data is collected, and to what extent is it processed?
We will process the data you have entered into our contact forms—specifically, the information you have provided in the contact form fields—for the purpose described below.
Legal basis for the processing of personal data
Art. 6(1)(a) of the GDPR or Art. 9(2)(a) of the GDPR (consent through a clear affirmative action or conduct, or explicit consent)
Purpose of data processing
We will use the data collected via our contact form(s) solely for the purpose of processing the specific inquiry submitted through the contact form.
Duration of storage
Once your request has been processed, the collected data will be deleted immediately, unless there are any legal retention requirements.
Right to Withdrawal and Right to Erasure
The options for revocation and deletion are governed by the general provisions regarding the right of revocation and the right to erasure under data protection law, as described below in this Privacy Policy.
Requirement to Provide Personal Information
Use of the contact forms is voluntary and is not required by contract or by law. You are not required to contact us via the contact form; you may also use the other contact options listed on our website. If you wish to use our contact form, you must fill out the fields marked as required. If you do not provide the necessary information in the contact form, you will either be unable to submit your inquiry, or we will unfortunately be unable to process it.
Automated Credit Check / Scoring
If you wish to enter into a contract with us, we reserve the right to process your personal data exclusively by automated means in order to verify your creditworthiness. We are also authorized to make such an automated decision pursuant to Article 22(2)(a) of the GDPR. Whether or not the contract can be concluded depends on the result of the automated creditworthiness check. During a creditworthiness check, statistical probabilities of default are calculated. The credit report may contain probability values (score values) calculated using scientifically recognized mathematical and statistical methods. These methods use a variety of factors—such as income, address information, occupation, marital status, and past payment history—to assess the customer’s future risk of default. The result is expressed as a payment value (known as a “score”). The information obtained in this way forms the basis for our decision regarding the establishment, execution, or termination of a contractual relationship. If you believe that you have been wrongfully excluded from entering into a contract as a result of the credit check, please feel free to explain your position to us via email. We will then review the automated decision in accordance with Article 22(3) of the GDPR on a case-by-case basis. In order to conduct the credit check, we are permitted to store and process your personal data in accordance with Article 6(1)(b) of the GDPR.
In connection with the upcoming contract, we will transfer your data to the following provider(s) in the cases listed below:
Creditreform Bonn Rossen, LLC:
Our company regularly checks your creditworthiness when entering into contracts and, in certain cases where there is a legitimate interest, also for existing customers. To this end, we work with Creditreform Bonn Rossen KG, Graurheindorfer Str. 92, 53117 Bonn, Germany (https://www.creditreform.de/bonn), from which we receive the necessary data. On behalf of Creditreform Bonn Rossen KG, we are providing you with the following information in advance, in accordance with Article 14 of the EU GDPR:
Creditreform Bonn Rossen KG is a consumer credit reporting agency. It maintains a database that stores credit information on private individuals.
On this basis, Creditreform Bonn Rossen KG provides credit reports to its customers. Customers include, for example, banks, leasing companies, insurance companies, telecommunications companies, debt collection agencies, mail-order, wholesale, and retail companies, as well as other businesses that supply goods or provide services. In accordance with legal provisions, a portion of the data contained in the credit report database is also used to supply other corporate databases, including for use in address-based marketing.
The Creditreform Bonn Rossen KG database stores, in particular, information regarding the name, address, date of birth, email address (if applicable), payment history, and ownership interests of individuals. The purpose of processing the stored data is to provide information regarding the creditworthiness of the person in question. The legal basis for the processing is Article 6(1)(f) of the EU GDPR. Accordingly, information regarding this data may only be provided if a customer credibly demonstrates a legitimate interest in obtaining this information. If data is transferred to countries outside the EU, this is done on the basis of the so-called “Standard Contractual Clauses,” which you can find at the following link:
http://eur-lex.europa.eu/legal-content/DE/TXT/PDF/?uri=CELEX:32001D0497&from=DE
can view or have sent to them from there.
The data is stored for as long as access to it is necessary to fulfill the purpose of storage. Access to the data is generally necessary for an initial storage period of three years. After this period expires, a review is conducted to determine whether continued storage is necessary; if not, the data is deleted to the exact day. If a matter is resolved, the data is deleted to the exact day three years after resolution. Entries in the debtor registry are deleted to the exact day in accordance with § 882e ZPO three years after the date of the entry order.
Legitimate interests within the meaning of Article 6(1)(f) of the EU GDPR may include: credit decisions, business development, ownership interests, claims, credit checks, insurance contracts, and enforcement information. You have the right to request information from Creditreform Bonn Rossen KG regarding the data it has stored about you. If the data stored about you is incorrect, you have the right to have it corrected or deleted. If it cannot be immediately determined whether the data is incorrect or correct, you have the right to have the relevant data blocked until the matter is clarified. If your data is incomplete, you may request that it be completed.
If you have given your consent to the processing of the data stored by Creditreform Bonn Rossen KG, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of the processing of your data that took place on the basis of your consent up until the time of withdrawal.
If you have any concerns, requests, or complaints regarding data protection, you can contact the Data Protection Officer at Creditreform Bonn Rossen KG at any time. The Data Protection Officer will assist you promptly and confidentially with any questions you may have regarding data protection. You may also file a complaint regarding Creditreform Bonn Rossen KG’s processing of your data with the State Data Protection Commissioner responsible for your federal state.
The data that Creditreform Bonn Rossen KG has stored about you comes from publicly available sources, debt collection agencies, and their clients.
To assess your creditworthiness, Creditreform Bonn Rossen KG calculates a score based on your data. The score takes into account data on your age and gender, address information, and, in some cases, payment history. These data points are factored into the score calculation with varying weights. Creditreform Bonn Rossen KG’s clients use these scores as a tool to help them make their own credit decisions.
Right to object:
The processing of data stored by Creditreform Bonn Rossen KG is carried out for compelling legitimate reasons related to creditor and credit protection, which generally outweigh your interests, rights, and freedoms, or serves to assert, exercise, or defend legal claims. You may object to the processing of your data only if there are reasons arising from your specific situation that must be substantiated. If such specific reasons are demonstrably present, the data will no longer be processed. If you object to the processing of your data for advertising and marketing purposes, the data will no longer be processed for these purposes.
The controller within the meaning of Article 4(7) of the EU GDPR is Creditreform Bonn Rossen KG, Graurheindorfer Str. 92, 53117 Bonn, Germany (https://www.creditreform.de/bonn). You can contact Creditreform Bonn Rossen KG with any questions using the following contact information: Tel.: +49 228 26794-0, Fax: +49 228 26794-919, Email: info@bonn.creditreform.de
You can contact the responsible data protection officer using the following contact information: Creditreform Bonn Rossen KG, Data Protection Officer, Graurheindorfer Str. 92, 53117 Bonn, Germany, https://www.creditreform.de/bonn.
Statistical Analysis of Visits to This Website - Web Tracker
When you access this website or individual files on the website, we collect, process, and store the following data: IP address, the website from which the file was accessed, the file name, the date and time of access, the amount of data transferred, and a notification regarding the success of the access (so-called web log). We use this access data exclusively in a non-personalized form to continuously improve our website and for statistical purposes. We also use the following web trackers to analyze visits to this website:
Custom Audiences
On our website, we use the Custom Audiences service provided by Meta Platforms Ireland Ltd., Merrion Road, D04 X2K5 Dublin 4, Ireland, email: impressum-support@support.facebook.com, website: http://facebook.com/. Personal data is also transferred to the United States. With regard to the transfer of personal data to the United States, there is an adequacy decision by the European Commission regarding the EU-US Data Privacy Framework pursuant to Article 45 of the GDPR (hereinafter: DPF— https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en ). The service provider is certified under the DPF, meaning that the standard level of protection provided by the GDPR applies to such transfers.
The legal basis for the processing of personal data is your consent pursuant to Article 6(1)(a) of the GDPR or Article 9(2)(a) of the GDPR, which you provided on our website.
Facebook Custom Audience is an advertising tool from Facebook that allows you to run targeted advertising campaigns aimed at visitors to your page.
You can view the provider's certification under the EU-U.S. Data Privacy Framework at https://www.dataprivacyframework.gov/list.
You may withdraw your consent at any time. For more information on how to withdraw your consent, please refer to the consent form itself or the end of this Privacy Policy.
For more information on how the transferred data is handled, please see the provider's privacy policy at https://www.facebook.com/privacy/policy/.
The provider also offers an opt-out option at https://www.facebook.com/privacy/policy/.
Facebook Connect
On our website, we use the Facebook Connect service provided by Meta Platforms Ireland Ltd., Merrion Road, D04 X2K5 Dublin 4, Ireland, email: impressum-support@support.facebook.com, website: http://www.facebook.com/. Personal data is also transferred to the United States. With regard to the transfer of personal data to the United States, there is an adequacy decision by the European Commission regarding the EU-US Data Privacy Framework pursuant to Article 45 of the GDPR (hereinafter: DPF— https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en ). The service provider is certified under the DPF, meaning that the standard level of protection provided by the GDPR applies to such transfers.
The legal basis for the processing of personal data is your consent pursuant to Article 6(1)(a) of the GDPR or Article 9(2)(a) of the GDPR, which you provided on our website.
With Facebook Connect, users can use their Facebook profile to log in to other web services more easily.
You can view the provider's certification under the EU-U.S. Data Privacy Framework at https://www.dataprivacyframework.gov/list.
You may withdraw your consent at any time. For more information on how to withdraw your consent, please refer to the consent form itself or the end of this Privacy Policy.
For more information on how the transferred data is handled, please see the provider's privacy policy at https://www.facebook.com/privacy/policy/.
The provider also offers an opt-out option at https://www.facebook.com/privacy/policy/.
Google Analytics
We use the Google Analytics service on our website, provided by Google Ireland Ltd., Gordon House, Barrow Street, 4 Dublin, Ireland, email: support-deutschland@google.com, website: https://www.google.com/. Personal data is also transferred to the United States. With regard to the transfer of personal data to the United States, there is an adequacy decision by the European Commission regarding the EU-US Data Privacy Framework pursuant to Article 45 of the GDPR (hereinafter: DPF— https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en ). The service provider is certified under the DPF, meaning that the standard level of protection provided by the GDPR applies to such transfers.
The legal basis for the processing of personal data is your consent pursuant to Article 6(1)(a) of the GDPR or Article 9(2)(a) of the GDPR, which you provided on our website.
Google Analytics is a web tracker that analyzes the behavior of website visitors and their interactions with our website, and provides us with reports and forecasts regarding the content and products on our website and their popularity (known as tracking). We have integrated Google Analytics so that the service can compile an analysis of website users’ browsing behavior. To this end, Google collects data on visitors’ interactions with our website and, where applicable, existing information derived from cookies or other storage technologies, and compiles this data into statistical reports for us. Google Analytics uses data processing technologies that enable the tracking of individual visitors and their interactions with other Google services, such as the Google Ads advertising network. Data from other Google services is also used to fill data gaps and generate comprehensive statistics on the content of our website using machine learning technologies, modeled statistics, and forecasting functions. If Google Analytics is active on our website, the data collected by Google Analytics is transferred to servers operated by Google Ireland Limited. As part of data processing on our behalf, personal data may also be transferred to the servers of the parent company, Google LLC, 1600 Amphitheatre Parkway, 94043 Mountain View, United States. We use Google Analytics to continuously optimize our website and improve its availability. This is known as audience measurement.
For the processing itself, the service—or we—collect the following data: Data regarding site visitors’ interactions with the website’s content; data regarding the use of the services displayed on our website; data from external Google services, to the extent that they interact with our website—such as advertising data or data regarding advertising behavior; data regarding approximate geographic location, the browser used, the operating system, and other information about the device used.
Google Analytics will store the data relevant to web tracking for as long as necessary to fulfill the web service that has been booked. Data collection and storage are anonymized. To the extent that individual interactions by site visitors make it possible to subsequently link specific actions to a specific individual, we will delete the collected data once the purpose has been achieved. The data will be deleted at the latest when it is no longer subject to any statutory retention requirements. As a rule, we will delete this data after 12 months at the latest. You can view the provider’s certification under the EU-U.S. Data Privacy Framework at https://www.dataprivacyframework.gov/list.
You may withdraw your consent at any time. For more information on how to withdraw your consent, please refer to the consent form itself or the end of this Privacy Policy.
For more information on how the transferred data is handled, please see the provider's privacy policy at https://policies.google.com/privacy.
The provider also offers an opt-out option at https://tools.google.com/dlpage/gaoptout?hl=de.
Google Tag Manager
We use the Google Tag Manager service on our website, provided by Google Ireland Ltd., Gordon House, Barrow Street, 4 Dublin, Ireland, email: support-deutschland@google.com, website: https://www.google.com/. Personal data is also transferred to the United States. With regard to the transfer of personal data to the United States, there is an adequacy decision by the European Commission regarding the EU-US Data Privacy Framework pursuant to Article 45 of the GDPR (hereinafter: DPF— https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en ). The service provider is certified under the DPF, meaning that the standard level of protection provided by the GDPR applies to such transfers.
The legal basis for the processing of personal data is your consent pursuant to Article 6(1)(a) of the GDPR or Article 9(2)(a) of the GDPR, which you provided on our website.
Google Tag Manager provides a technical platform for running other web tools and web tracking programs using so-called “tags” and for managing them collectively. In this context, Google Tag Manager stores cookies on your computer and, to the extent that web tracking tools are run via Google Tag Manager, analyzes your browsing behavior (known as “tracking”). The data generated by the “tags” is consolidated, stored, and processed by Google Tag Manager within a unified user interface. All integrated “tags” are listed separately in this privacy policy. When you use our website with Google Tag Manager “tags” enabled, data—including, in particular, your IP address and your user activities—is transmitted to Google’s servers. The tracking tools used in Google Tag Manager ensure, through IP anonymization of the source code, that your IP address is anonymized by Google Tag Manager before transmission. Tag Manager allows us to link and analyze metrics from various service providers (Google and third parties) based on what is known as “tag management.” Google Tag Manager helps us compile reports on website activity and manage the web tools on our website.
For the processing itself, the service—or we—collect the following data: Cookies, web tracking data, outgoing or incoming links, and information generated during the integration and activation of JavaScript code on the website by Google Tag Manager and the web tools triggered by Google Tag Manager.
You can view the provider's certification under the EU-U.S. Data Privacy Framework at https://www.dataprivacyframework.gov/list.
You may withdraw your consent at any time. For more information on how to withdraw your consent, please refer to the consent form itself or the end of this Privacy Policy.
For more information on how the transferred data is handled, please see the provider's privacy policy at https://policies.google.com/privacy.
The provider also offers an opt-out option at https://policies.google.com/privacy.
Integration of external web services and processing of data outside the EU
On our website, we use active content from external providers, known as web services. When you visit our website, these external providers may receive personal information about your visit to our website. This may involve the processing of data outside the EU. You can prevent this by installing an appropriate browser plugin or by disabling the execution of scripts in your browser. This may result in limited functionality on the websites you visit.
We use the following external web services:
Legal text snippets and modules
On our website, we use the Rechtstextsnippet service and modules provided by Website-Check GmbH, Beethovenstraße 24, 66111 Saarbrücken, Germany; email: support@website-check.de; website: https://www.website-check.de/. Personal data is transmitted exclusively to servers located in the European Union.
The legal basis for the processing is Article 6(1)(c) of the GDPR. Using this service helps us comply with our legal obligations.
This service is used to load the content of our legal texts onto our website. The integration on our site ensures that the most up-to-date legal texts are loaded. This integration may also be used to load additional technical modules related to the legal texts or legally required elements.
You can find out what rights you have regarding the processing of your data at the end of this privacy policy.
For more information on how the transferred data is handled, please see the provider's privacy policy at https://www.website-check.de/datenschutzerklaerung/.
Website Check Seal
We use the "Website-Check Siegel" service on our site, provided by Website-Check GmbH, Beethovenstraße 24, 66111 Saarbrücken, Germany; email: support@website-check.de; website: https://www.website-check.de/. Personal data is transmitted exclusively to servers located in the European Union.
The legal basis for the processing of personal data is our legitimate interest, in accordance with Article 6(1)(f) of the GDPR. Our legitimate interest lies in achieving the purpose described below.
The Website-Check GmbH script is used to technically integrate the Website-Check seal. We use this seal to demonstrate that we take data protection very seriously. Data is transmitted to Website-Check GmbH for the purpose of delivering and displaying the seal on our website.
With regard to the processing of your data, you have the right to object as set forth in Article 21. You can find more information at the end of this Privacy Policy.
For more information on how the transferred data is handled, please see the provider's privacy policy at https://www.website-check.de/datenschutzerklaerung/.
Weglot
On our website, we use the Weglot service provided by Weglot, 7 Cité Paradis, 75010 Paris, France; email: privacy@weglot.com; website: https://weglot.com/de/. Personal data is transmitted exclusively to servers located in the European Union.
The legal basis for the processing of personal data is your consent pursuant to Article 6(1)(a) of the GDPR or Article 9(2)(a) of the GDPR, which you provided on our website.
This service is a plugin that we need to make the website available in different languages.
You may withdraw your consent at any time. For more information on how to withdraw your consent, please refer to the consent form itself or the end of this Privacy Policy.
For more information on how the transferred data is handled, please see the provider's privacy policy at https://weglot.com/de/privacy/.
Social Plug-In – “Facebook by META”
What personal data is collected, and to what extent is it processed?
We have integrated a social plug-in from the social network “Facebook by META” into our website, which is operated by Meta Platforms Ireland Ltd., Merrion Road, D04 X2K5 Dublin 4, Ireland, email: impressum-support@support.facebook.com, website: http://www.facebook.com/ (“Facebook by META”). When you visit a page that contains such a plug-in, your browser automatically establishes a background connection to the servers of Facebook by META. The content of the plug-in is transmitted directly from Facebook by META to your browser and is merely integrated into our site. Through this integration, Facebook by META receives the information that your browser has loaded a specific page of our website. This applies even if you do not have a Facebook by META profile or are not currently logged in to Facebook by META. This information (including your IP address) is transmitted directly from your browser to a Facebook by META server in Ireland and stored there. If you are logged in to Facebook by META, Facebook by META can immediately associate your visit to our website with your Facebook by META profile. If you interact with the plug-ins—for example, by clicking the “Like” button or posting a comment—this information is also transmitted directly to a Facebook by META server and stored there. The information is also published on your Facebook by META profile and displayed to your Facebook by META contacts whom you have authorized to view it.
Legal basis for the processing of personal data
Art. 6(1)(a) of the GDPR (if you have registered with “Facebook by META”) and Art. 6(1)(f) of the GDPR (if you have not registered with Facebook by META). To the extent that processing is based on Article 6(1), first sentence, subparagraph (f) of the GDPR, the website operator’s legitimate interest is to enable users to interact with the website operator’s content on Facebook by META.
Purpose of data processing
The primary purpose of data collection is to offer you a way to interact socially through Facebook by META and thereby make our website more interactive. You can find information about the scope of data collection and the further processing and use of the data you provide by Facebook by META, as well as your rights in this regard and the settings available to protect your privacy, in Facebook by META’s privacy policy: https://www.facebook.com/privacy/policy/
Duration of storage
Facebook by META will store the data relevant to the provision of the web service for as long as necessary. To the extent that the data is subject to statutory retention requirements, it will be deleted once the retention period has expired.
Right to object and request deletion
If you do not want the Facebook by META social plug-in to run, you can prevent it from doing so by installing an appropriate add-on or script blocker. If you do not want Facebook by META to associate the data collected via our website with your Facebook by META profile, you must log out of Facebook by META before visiting our website. The options for objection and deletion are otherwise governed by the general provisions regarding the right to object and the right to erasure under data protection law, as described later in this Privacy Policy.
Data Security and Privacy, Email Communication
Your personal data is protected through technical and organizational measures during collection, storage, and processing to ensure that it is not accessible to third parties. In the case of unencrypted email communication, we cannot guarantee complete data security during transmission to our IT systems; therefore, we recommend encrypted communication or sending information by mail for information requiring a high level of confidentiality.
Automatic Email Archiving
Scope of the processing of personal data
We would like to expressly point out that our email system uses an automated archiving process. All incoming and outgoing emails are digitally archived in an audit-proof manner through this process.
Legal basis for the processing of personal data
Art. 6(1)(c) of the GDPR (legal obligation). The legal obligation consists of complying with tax and commercial law requirements (e.g., Sections 146 and 147 of the German Fiscal Code (AO), Sections 238 and 257 of the German Commercial Code (HGB)).
Purpose of data processing
The purpose of archiving is to comply with tax law requirements (e.g., Sections 146 and 147 of the German Fiscal Code [AO]—the obligation to retain emails relevant to tax matters) and commercial law requirements (e.g., Sections 238 and 257 of the German Commercial Code [HGB]—the obligation to archive business correspondence).
Duration of storage
Our email correspondence is stored until the expiration of retention requirements under tax and commercial law. The retention period may be up to 10 years.
Right to object and request deletion
You may object to the processing of your data at any time in accordance with Article 21 of the GDPR and request the erasure of your data in accordance with Article 17 of the GDPR. You can find information about your rights and how to exercise them at the bottom of this Privacy Policy.
Handling Application Materials
If you have any questions regarding our email archiving system, please contact our Data Protection Officer. Please also note that we only accept application documents in PDF format. Zipped files (WinZip, WinRAR, 7Zip, etc.) are filtered out by our security systems and will not be delivered. We do not accept applications in Word format or other file formats and will delete them unread. Please note that application documents sent via unencrypted email may be opened by third parties before they reach our IT systems. We assume that we are also permitted to respond to unencrypted application emails in an unencrypted manner. If you do not wish this, please let us know in your application email.
Right to access information and requests for correction – Deletion and restriction of data – Withdrawal of consent – Right to object
Right to information
You have the right to request confirmation as to whether we process your personal data. If this is the case, you have the right to access the information specified in Article 15(1) of the GDPR, provided that this does not infringe upon the rights and freedoms of others (see Article 15(4) of the GDPR). We would also be happy to provide you with a copy of the data.
Right to correction
Pursuant to Article 16 of the GDPR, you have the right to have us correct any personal data we have on file that may be incorrect (such as your address, name, etc.) at any time. You may also request that we complete any data we have stored about you at any time. We will make the necessary changes immediately.
Right to erasure
Pursuant to Article 17(1) of the GDPR, you have the right to request that we erase the personal data we have collected about you if
- the data is no longer needed;
- the legal basis for the processing has ceased to exist without replacement due to the withdrawal of your consent;
- you have objected to the processing and there are no legitimate grounds for the processing;
- your data is being processed unlawfully;
- a legal obligation requires it, or data has been collected in accordance with Article 8(1) of the GDPR.
Pursuant to Article 17(3) of the GDPR, this right does not apply if
- the processing is necessary for the exercise of the right to freedom of expression and information;
- your data has been collected based on a legal obligation;
- the processing is necessary for reasons of public interest;
- the data is necessary for the assertion, exercise, or defense of legal claims.
Right to restriction of processing
Pursuant to Article 18(1) of the GDPR, you have the right to request the restriction of the processing of your personal data in certain cases.
This is the case when
- you dispute the accuracy of your personal data;
- the processing is unlawful and you do not consent to its erasure;
- the data is no longer needed for the purpose for which it was processed, but the collected data is necessary for the establishment, exercise, or defense of legal claims;
- an objection to the processing has been lodged pursuant to Article 21(1) of the GDPR, and it is still unclear which interests prevail.
Right of withdrawal
If you have given us your explicit consent to the processing of your personal data (Art. 6(1)(a) GDPR or Art. 9(2)(a) GDPR), you may revoke this consent at any time. Please note that this does not affect the lawfulness of the processing carried out on the basis of your consent prior to its revocation.
Right to object
Pursuant to Article 21 of the GDPR, you have the right to object at any time to the processing of your personal data that was collected on the basis of Article 6(1)(f) (in the context of a legitimate interest). You are entitled to this right only if there are specific circumstances that justify objecting to the storage and processing of your data.
How do you exercise your rights?
You can exercise your rights at any time by contacting us using the contact information below:
C.ENTER GmbH & Co. KG
Eisenerzstr. 36
53819 Neunkirchen-Seelscheid
Germany
Email: info@cdotenter.de
Fax: +49 (0) 2247 9239 19
Right to data portability
Pursuant to Article 20 of the GDPR, you have the right to receive the personal data concerning you. We will provide the data in a structured, commonly used, and machine-readable format. The data may be sent either to you or to a data controller designated by you.
Upon request, we will provide you with the following data in accordance with Article 20(1) of the GDPR:
- Data collected on the basis of explicit consent pursuant to Article 6(1)(a) of the GDPR or Article 9(2)(a) of the GDPR;
- Data that we have received from you pursuant to Article 6(1)(b) of the GDPR in connection with existing contracts;
- Data that has been processed as part of an automated procedure.
We will transfer your personal data directly to the data controller of your choice, to the extent that this is technically feasible. Please note that, pursuant to Article 20(4) of the GDPR, we are not permitted to transfer data that would infringe upon the freedoms and rights of other individuals.
Right to lodge a complaint with the supervisory authority pursuant to Article 77(1) of the GDPR
If you suspect that your data is being processed unlawfully on our website, you may, of course, seek a judicial resolution of the matter at any time. In addition, you may pursue any other legal remedies available to you. Irrespective of this, pursuant to Article 77(1) of the GDPR, you have the option to contact a supervisory authority. You have the right to lodge a complaint under Article 77 of the GDPR in the EU Member State where you reside, where you work, and/or where the alleged infringement occurred; that is, you may choose the supervisory authority to which you wish to turn from among the locations mentioned above. The supervisory authority to which the complaint was submitted will then inform you of the status and outcome of your complaint, including the possibility of a judicial remedy under Article 78 of the GDPR.
Created by:
© DURY LEGAL Attorneys at Law – www.dury.de
© Website-Check GmbH – www.website-check.de