Data protection

We are pleased that you are visiting our homepage and thank you for your interest in our company. Dealing with our customers and interested parties is a matter of trust. The trust placed in us is very important to us and therefore the importance and obligation to handle your data carefully and to protect it from misuse.

To ensure that you feel safe and comfortable when visiting our website, we take the protection of your personal data and its confidential treatment very seriously. Therefore, we act in accordance with the applicable legislation on the protection of personal data and data security. With these notes on data protection, we would therefore like to inform you about when we store which data and how we use it - naturally in compliance with the applicable legislation.

In particular, KRALLMANN AG follows the EU General Data Protection Regulation as well as the current national data protection laws. When using the Internet, we are guided by the Telemedia Act (TMG) of the Federal Republic of Germany to protect your personal data. In the following, we explain what information we collect during your visit to our websites and how it is used.

Overview
I. Name and address of the responsible person

II. Name and address of the data protection officer

III. general information on data processing

IV. Provision of the website and creation of log files

V. Use of cookies

VI. contact form/e-mail contact

VII. consulting and advertising

VIII. rights of the data subject

IX. Right to complain to a supervisory authority

X. Security

XI. Declaration of consent of the user


Name and address of the controller
The responsible party within the meaning of the DSGVO and other national data protection laws of the member states as well as other data protection regulations is:

KRALLMANN AG
UPPER WEST
Kantstr. 164
10623 Berlin

Phone: +49 (0)30 8020836-6
Fax: +49 (0)30 8020836-890
E-mail: info@krallmann.com


Name and address of the data protection officer
The data protection officer of the responsible party is:

Andreas Thurmann
DataSolution LUD GmbH
Isarstr. 13
14974 Ludwigsfelde
Germany
mail@ds-lud.de

www.datenschutzberater365.de


General information on data processing

1. scope of the processing of personal data

As a matter of principle, we collect and use personal data of our users only to the extent that this is necessary for the provision of a functional website as well as our content and services. The collection and use of personal data of our users is regularly carried out only with the consent of the user. An exception applies in those cases where it is not possible to obtain prior consent for factual reasons and the processing of the data is permitted by legal regulations.

2. legal basis for the processing of personal data

Insofar as we obtain the consent of the data subject for processing operations of personal data, Art. 6 (1) lit. a DSGVO serves as the legal basis. When processing personal data that is necessary for the performance of a contract to which the data subject is a party, Art. 6 (1) lit. b DSGVO serves as the legal basis. This also applies to processing operations that are necessary for the performance of pre-contractual measures. If processing of personal data is necessary to comply with a legal obligation (statutory provisions) to which our company is subject (e.g. federal registration laws), Art. 6 (1) lit. c DSGVO serves as the legal basis. If the processing is necessary to protect a legitimate interest of our company or a third party and the interests, fundamental rights and freedoms of the data subject do not outweigh the former interest, Art. 6 (1) f DSGVO serves as the legal basis for the processing.

3. Data deletion and storage period

The personal data of the data subject will be deleted or blocked as soon as the purpose of storage ceases to apply. Storage may take place beyond this,

if this has been provided for by the European or national legislator in Union regulations, laws or other regulations to which the controller is subject. Data will also be blocked or deleted if a storage period prescribed by the aforementioned standards expires, unless there is a need for further storage of the data for the conclusion or performance of a contract.

Provision of the website and creation of log files

1. description and scope of data processing

Each time our website is called up, our system automatically collects data and information from the computer system of the calling computer. The following data is collected in this context:

Information about the browser type and the version used.

The operating system of the user

The IP address of the user

Date and time of access

Websites from which the user's system accesses our website

Web pages that are accessed by the user's system via our website

The data is also stored in the log files of our system. This data is not stored together with other personal data of the user. Personal user profiles cannot be formed. The stored data is only evaluated for statistical purposes.

2. legal basis for data processing

The legal basis for the temporary storage of the data and the log files is the processing for the protection of our legitimate interest, i.e. by KRALLMANN AG.

3. purpose of data processing

The temporary storage of the IP address by the system is necessary to enable delivery of the website to the user's computer. For this purpose, the IP address of the user must remain stored for the duration of the session.

The storage in log files is done to ensure the functionality of the website. In addition, we use the data to optimize the website and to ensure the security of our information technology systems. An evaluation of the data for marketing purposes does not take place in this context.

Our legitimate interest in data processing also lies in these purposes.

4. Duration of storage

The data will be deleted as soon as they are no longer required to achieve the purpose for which they were collected. In the case of the collection of data for the provision of the website, this is the case when the respective session has ended.

In the case of storage of data in log files, this is the case after seven days at the latest. Storage beyond this period is possible. In this case, the IP addresses of the users are deleted or alienated, so that an assignment of the calling client is no longer possible.

5. possibility of objection and elimination

The collection of data for the provision of the website and the storage of the data in log files is mandatory for the operation of the website. Consequently, there is no possibility of objection on the part of the user.

Use of cookies

1. description and scope of data processing

Cookies are small files that allow us to store specific information related to you, the user, on your computer while you are visiting one of our websites. Cookies help us to determine the frequency of use and the number of users of our websites, as well as to make our offers as convenient and efficient as possible for you.

We use so-called "session cookies", which are temporarily stored exclusively for the duration of your use of our websites. The session cookies are stored on your data carrier in order to ensure certain settings and functionalities on our websites via your browser. The cookies we use are deleted after the end of the browser session, i.e. after you close your browser.

We also use cookies on our website, which enable an analysis of the user's surfing behavior. In this way, the following data can be transmitted: Search terms entered, frequency of page views, use of website functions. The user data collected in this way is pseudonymized by technical precautions. Therefore, an assignment of the data to the calling user is no longer possible. The data is not stored together with other personal data of the user. When calling up our website, the user is informed about the use of cookies for analysis purposes and his consent to the processing of personal data used in this context is obtained. In this context, a reference to this privacy policy is also made.

2. Legal basis for data processing

The legal basis for the processing of personal data using technically necessary cookies is our legitimate interest in data processing.

3. Purpose of data processing

The purpose of using technically necessary cookies is to simplify the use of websites for users. Some functions of our website cannot be offered without the use of cookies. For these, it is necessary that the browser is recognized even after a page change. The user data collected by technically necessary cookies are not used to create user profiles.

The analysis cookies are used for the purpose of improving the quality of our website and its content. Through the analysis cookies, we learn how the website is used and can thus constantly optimize our offer.

4. duration of storage, possibility of objection and removal

Cookies are stored on the user's computer and transmitted to our site by the user. Therefore, you as a user also have full control over the use of cookies. By changing the settings in your Internet browser, you can disable or restrict the transmission of cookies. Cookies that have already been stored can be deleted at any time. This can also be done automatically. If cookies are deactivated for our website, it may no longer be possible to use all functions of the website in full.

We give the users of our website the opportunity to agree to the storage of cookies and execution of scripts for purposes of analysis (statistics) and marketing via our cookie banner of Cookiebot when visiting our website for the first time.

5. Supplementary information

In addition to the above information on the use of cookies, we point out the following:

Use of Google Analytics, Ad Words, Google Remarketing and Google Audience.

Our website may use Google Analytics, Google DoubleClick cookies, Google Convers tracking, Google Remarketing and Google Audience. These are services of Google Inc, 1600 Amphitheatre Parkway, Mountain View, CA 94043, United States ("Google"). We have concluded an order processing agreement with Google and fully implement the strict requirements of the German data protection authorities when using Google Analytics.

This offer uses Google Analytics, a web analytics service provided by Google Inc ("Google"). Google Analytics uses "cookies", which are text files placed on users' computers, to help the website analyze how users use the site. The information generated by the cookie about the use of this website by users is usually transmitted to a Google server in the USA and stored there. In the event that IP anonymization is activated on this website, however, Google will truncate the user's IP address beforehand within member states of the European Union or in other contracting states to the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there.
IP anonymization is active on this website. On behalf of the operator of this website, Google will use this information for the purpose of evaluating the use of the website by users, compiling reports on website activity and providing other services relating to website activity and internet usage to the website operator. The IP address transmitted by your browser as part of Google Analytics will not be merged with other data from Google. Users may refuse the use of cookies by selecting the appropriate settings on their browser, however please note that if you do this you may not be able to use the full functionality of this website. Users can also prevent the collection of data generated by the cookie and related to their use of the website (including your IP address) to Google and the processing of this data by Google by downloading and installing the browser plugin available at the following link: https://tools.google.com/dlpage/gaoptout?hl=de.

Google Tag Manager

This website uses Google Tag Manager. Google Tag Manager is a solution that allows marketers to manage website tags through one interface. The Tag Manager tool itself (which implements the tags) is a cookie-less domain and does not collect any personal data. The tool takes care of triggering other tags, which in turn may collect data. Google Tag Manager does not access this data. If a deactivation has been made at the domain or cookie level, this remains in place for all tracking tags implemented with Google Tag Manager.

Google Analytics Remarketing

This function allows us to link the advertising target groups created with Google Analytics Remarketing with the cross-device functions of Google AdWords and Google DoubleClick. In this way, interest-based, personalized advertising messages that have been adapted to you depending on your previous usage and surfing behavior on one end device (e.g. cell phone) can also be displayed on another of your end devices (e.g. tablet or PC).

To support this feature, Google Analytics collects Google-authenticated IDs of users, which are temporarily linked to our Google Analytics data to define and create target groups for cross-device ad advertising.

You can permanently opt out of cross-device remarketing/targeting by disabling personalized advertising in your Google account; follow this link: https://www.google.com/settings/ads/onweb/.

The aggregation of the collected data in your Google account takes place exclusively on the basis of our legitimate interest (Art. 6 (1) lit f DSGVO) and the possibility to object (Art. 21 DSGVO) on our website and in your Google account. In the case of data collection processes that are not merged in your Google account (e.g. because you do not have a Google account or have objected to the merger), the collection of data is also based on Art. 6 (1) lit. f DSGVO.

The legitimate interest arises from the fact that the website operator has an interest in the anonymized analysis of website visitors for advertising purposes. Further information and the privacy policy can be found in Google's privacy policy at: https://policies.google.com/technologies/ads?hl=de.

Google Analytics Audience

Our website uses GA Audience. This service uses, among other things, cookies that are stored on your computer as well as other mobile devices (e.g. smartphones, tablets, etc.) and that enable an analysis of the use of the respective devices. The data is in part evaluated across devices.

Google Audience receives access to the cookies created in the context of the use of Google AdWords and Google Analytics. In the course of use, data, such as in particular the IP address and activities of the users, may be transmitted to a server of the company Google Inc. and stored there. Google Inc. may transfer this information to third parties if required to do so by law, or if such data is processed by third parties.

You can prevent the collection and forwarding of personal data (esp. your IP address) as well as the processing of this data by deactivating the execution of JavaScript in your browser or installing a tool such as 'NoScript'. You can also prevent the collection of data generated by the Google cookie and related to your use of the website (including your IP address) to Google and the processing of this data by Google by downloading and installing the browser plugin available at the following link (http://tools.google.com/dlpage/gaoptout?hl=de). Further information on data protection when using GA Audience can be found at the following link: https://support.google.com/analytics/answer/2700409?hl=en&ref_topic=2611283.

Deactivation of Google advertising

(https://policies.google.com/technologies/ads?hl=de) or on the deactivation page of the Network Advertising Initiative (http://www.networkadvertising.org/managing/opt_out.asp).

Analysis by Leadfeeder (lead generation tool)

We use the services of so-called lead generation tools. Lead generation (prospect acquisition) is a marketing term. A lead is a qualified prospective customer, who on the one hand is interested in a company or a product and on the other hand gives the advertiser his address and similar contact data (lead = data record) for a further dialog build-up and therefore with high probability becomes a customer. Generating high-quality leads is a fundamental task for acquiring new customers. Address data of potential interested parties can be generated online as well as offline for specific target groups and in these purposes also lies our legitimate interest in data processing according to Art. 6 para. 1 lit. f DSGVO. We use the Leadfeeder service. This uses Google Analytics data in order to recognize company visitors. This is a service of Liidio Oy, Mikonkatu 17 C, Helsinki 00100, Finland. Leadfeeder's privacy policy can be found at https://www.leadfeeder.com/privacy/.

Use of social media plugins
Use of Facebook

The "Facebook Share Button" is used on this website. This is a plugin of the social network Facebook, 1601 South California Avenue, Palo Alto, CA 94304, USA integrated. You can recognize the Facebook plugins by the Facebook logo or the "Like button" ("Like") on our site. You can find an overview of the Facebook plugins here: developers.facebook.com/docs/plugins/.

When you visit our pages, a direct connection is established between your browser and the Facebook server after the plugin is activated. Facebook thereby receives the information that you have visited our site with your IP address. If you click the "Facebook button" while logged into your Facebook account, you can link the content of our pages on your Facebook profile. This allows Facebook to associate the visit to our pages with your user account. We would like to point out that we, as the provider of the pages, have no knowledge of the content of the transmitted data or its use by Facebook.

For more information, please refer to the privacy policy of facebook at https://www.facebook.com/policy.php. If you do not want Facebook to be able to associate your visit to our pages with your Facebook user account, please log out of your Facebook user account.

Use of LinkedIn

On our website you will find plugins of the social network LinkedIn respectively of LinkedIn Corporation, 2029 Stierlin Court, Mountain View, CA 94043, USA (hereinafter referred to as "LinkedIn"). You can recognize the LinkedIn plugins by the corresponding logo or the "Recommend" button.

When you visit our pages, a direct connection is established between your browser and the LinkedIn server via the plugin. LinkedIn thereby receives the information that you have visited our site with your IP address. If you click the LinkedIn button while logged into your LinkedIn account, you can link the content of our pages on your LinkedIn profile. This allows LinkedIn to associate the visit to our pages with your user account. We would like to point out that we, as the provider of the pages, have no knowledge of the content of the transmitted data or its use by LinkedIn. For more information on this, please refer to LinkedIn's privacy policy at http://www.linkedin.com/static?key=privacy_policy&trk=hb_ft_priv.

Use of Xing

The "XING Share Button" is used on this website. When you access this website, a connection is briefly established via your browser to servers of XING AG ("XING"), with which the "XING Share Button" functions (in particular the calculation/display of the counter value) are provided. XING does not store any personal data about you when you call up this website. In particular, XING does not store any IP addresses. There is also no evaluation of your usage behavior via the use of cookies in connection with the "XING Share Button". The current data protection information on the "XING Share button" and supplementary information can be found on this website: https://www.xing.com/app/share?op=data_protection.

Contact form/e-mail contact

1. description and scope of data processing

A contact form is available on our website, which can be used for electronic contact. If a user takes advantage of this option, the data entered in the input mask is transmitted to us and stored. These data are:

Salutation/title

First and last name

Company

Address

E-mail address

Phone

Request

Alternatively, it is possible to contact us via the e-mail address provided. In this case, the user's personal data transmitted with the e-mail will be stored.

In this context, the data will not be passed on to third parties. The data will be used exclusively for processing the conversation.

2. legal basis for data processing

The legal basis for the processing of the data is Art. 6 para. 1 lit. a DSGVO if the user has given his consent.

The legal basis for the processing of the data is otherwise Art. 6 para. 1 lit. f DSGVO. If the contact aims at the conclusion of a contract, the additional legal basis for the processing is Art. 6 para. 1 lit. b DSGVO.

3. purpose of the data processing

When processing personal data when contacting us by e-mail, the necessary legitimate interest in processing the data exists.

4. duration of storage

The data will be deleted as soon as they are no longer required to achieve the purpose for which they were collected. For personal data sent by e-mail, this is the case when the respective conversation with the user has ended. The conversation is terminated when it can be inferred from the circumstances that the matter in question has been conclusively clarified.

5. possibility of objection and elimination

The user has the option to object to the processing of his personal data at any time. For this purpose, we have set up the e-mail address datenschutz@krallmann.com.

We would like to point out that in the event of an objection, the conversation cannot be continued or we cannot create any offers, etc.

All personal data stored in the course of contacting us will be deleted in this case.

Support, consulting for corporate customers

1. description and scope of data processing

For the support and advice of corporate customers, we collect and use personal data. For corporate customers, in addition to the business contact or potential business contact, we store the contact person, telephone number and postal address. We obtain the information from various sources, either through an inquiry (e-mail or telephone), but also through events, trade fairs, business cards that our employees receive.

In this context, the data will not be disclosed to third parties. The data will be used exclusively for the above-mentioned purposes.

2. legal basis for data processing

The legal basis for processing the data is, moreover, our legitimate interest in data processing. If the contact is aimed at the conclusion of a contract, the additional legal basis for processing is the business initiation relationship or contractual relationship.

3. Purpose of data processing

We use this contact data exclusively for our own purposes and for the needs-based design of our own consulting activities.

4. duration of storage

In principle, no deletion period is provided for. However, if KRALLMANN AG has not had any contact with the company contact within 3 years, KRALLMANN AG will decide whether to delete the company contact.

If the contact is a pre-contractual relationship, the transmitted data will also be stored in our administration software and used for the execution of the contract.

5. possibility of objection and elimination

The company contact has the option to object to the processing of his personal data at any time. For this purpose, we have set up the e-mail address datenschutz@krallmann.com.

All personal data, including that of the contact person, stored for the business contact will be deleted in this case.

Online application for a job advertisement

1. description and scope of data processing

If you provide us with personal data as part of the application process, this data is divided into the following data types and data categories for collection, processing and / or use:

For the automated processing of your application, the following data will be collected and processed:

First name, last name, e-mail and, if applicable, also address/place, date of birth, title, telephone number, citizenship.

Additional questions depending on the respective job advertisement (e.g. driving license)

Curriculum vitae, in particular information on professional experience and training

Skills (e.g. Photoshop, MS Office)

Application photo

Qualifications, awards and language skills

Letter of motivation

Files and documents you upload, if any

E-mail address + password (login for user account).

We also store written, electronic communication that takes place between you and KRALLMANN AG. Furthermore, we process comments and evaluations that are written about you in the course of your application process.

If you submit an online application from our websites, this is done through the online application system of Prescreen International GmbH, Mariahilfer Straße 17, A-1060 Vienna, Austria. All booking data entered by you is transmitted in encrypted form. Prescreen is committed to handling your transmitted data in accordance with data protection regulations. It takes all organizational and technical measures to protect your data.

We use the personal data you have transmitted exclusively for processing your application for the advertised position. Your personal data will only be disclosed to persons involved in the application process. All employees entrusted with data processing are obliged to maintain the confidentiality of your data. We do not pass on your personal data to third parties unless you have consented to the passing on of data or we are obliged to pass on data due to legal provisions and/or official or court orders.

2. Legal basis for data processing

The legal basis for processing the data is the contract initiation relationship or the conclusion of a contract with the applicant. We will obtain your consent to store your data beyond the general time limits.

3. purpose of data processing

The processing of personal data from the input mask or the uploading of files serves us solely to process your application.

4. duration of storage

Your data will be automatically deleted within six months after completion of the specific application process. This does not apply if legal regulations prevent deletion, if further storage is required for the purpose of providing evidence, or if you have expressly agreed to longer storage. Two weeks before your data is deleted, you will receive an e-mail request from us asking whether your data may remain stored for a further period of 12 months.

If you prefer a longer storage period in the course of your application process (for example, in order to continue your application process later), we ask you to make these settings accordingly during registration.

5. possibility of objection and removal

The user has the option to object to the processing of his personal data at any time. For this purpose, we have set up the e-mail address datenschutz@krallmann.com. We would like to point out that in the event of an objection, the application will not be completed or the conversation will not be continued.

Rights of the data subject
If personal data is processed by you, you are a data subject within the meaning of the GDPR and you are entitled to the following rights vis-à-vis the controller:

You have a right to information about the personal data stored about you, about the purposes of processing, about any transfers to other bodies and about the duration of storage.

If data is incorrect or no longer necessary for the purposes for which it was collected, you may request that it be corrected, erased or restricted from processing. Where provided for in the processing procedures, you may also inspect your data yourself and correct it if necessary.

If grounds for objecting to the processing of your personal data arise from your particular personal situation, you may object to such processing insofar as the processing is based on a legitimate interest. The controller will no longer process the personal data concerning you unless it can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing is for the purpose of asserting, exercising or defending legal claims. If the personal data concerning you is processed for the purposes of direct marketing, you have the right to object at any time to processing of the personal data concerning you for the purposes of such marketing; this also applies to profiling, insofar as it is related to such direct marketing. If you object to the processing for direct marketing or profiling purposes, the personal data concerning you will no longer be processed for these purposes.

You have the right to revoke your declaration of consent under data protection law at any time. The revocation of consent does not affect the lawfulness of the processing carried out on the basis of the consent until the revocation.

If you have any questions about your rights and how to exercise them, please contact:

Responsible party

Data protection officer

KRALLMANN AG
UPPER WEST
Kantstr. 164
10623 Berlin

Phone: +49 (0)30 8020836-6
Fax: +49 (0)30 8020836-890

DataSolution LUD GmbH
Mr. Andreas Thurmann
Isarstr. 13
D-14974 Ludwigsfelde
Germany

Tel.: 03378 202513
Fax: 03378 202514

Right to complain to a supervisory authority
As a data subject, without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your residence or of the place of the alleged infringement, if you consider that the processing of personal data concerning you infringes data protection.

The supervisory authority to which the complaint is submitted will inform you about the status and results of your complaint, including the possibility of a judicial remedy.

More information can be found on the website of the Federal Commissioner for Data Protection and Freedom of Information. Follow the link.

Security

KRALLMANN AG uses technical and organizational security measures in accordance with Art. 32 DSGVO to protect your data managed by us against accidental or intentional manipulation, loss, destruction or against access by unauthorized persons. Our security measures are continuously improved in line with technological developments. Access to this data is only possible for a few authorized persons and persons with a special obligation to protect data who are involved in the technical, administrative or editorial management of data.

For security reasons and to protect the transmission of confidential content that you send to us as site operator, our website uses SSL or TLS encryption. This means that data you transmit via this website cannot be read by third parties. You can recognize an encrypted connection by the "https://" address line of your browser and the lock symbol in the browser line.


Declaration of consent of the user
By using our web pages and the offers contained therein, you consent to the storage by us of the personal data voluntarily submitted by you and to its processing and use in accordance with this privacy policy.

We reserve the right to change, update or amend this privacy policy at any time. Any revised Privacy Policy will only apply to Personal Data collected or modified after the effective date of the revised policy.


Status |November 2019