Data protection information for applicants
|
|
Contact details of the controllers:
|
|
|
Herbert Kircher GmbH Gewerbegebiet Neu Kupfer Flurweg 5 74635 Kupferzell
Manager:
Peter Kircher: Gewerbegebiet Neu Kupfer Flurweg 5 74635 Kupferzell Mail: info@kircher-transporte.de Phone: +49 (0) 7944 9130 - 0
Manager:
Hans Micha Kircher Gewerbegebiet Neu Kupfer Flurweg 5 74635 Kupferzell Mail: info@kircher-transporte.de Phone: +49 (0) 7944 9130 - 0
Manager:
Franz Peter Kircher Gewerbegebiet Neu Kupfer Flurweg 5 74635 Kupferzell Mail: info@kircher-transporte.de Phone: +49 (0) 7944 9130 - 0
|
|
|
Contact details of the data protection officer:
|
|
|
dsgvoschutzbrief.com - Lukmann Consulting GmbH Walter Lukmann Packerstrasse 183 A-8561 Söding
Mail: service@dsgvoschutzbrief.com
Phone: +49 7223 95 666 77
|
Definitions of data categories
|
|
|
Description of the data category
|
|
|
Career
|
Previous jobs and employers, periods of unemployment, military service.
|
|
Personal
Credentials
|
Name, title, address (private and professional), previous addresses, telephone number (home, work), identification numbers assigned by the data controller.
|
|
Personal details
|
Age, gender, date of birth, place of birth, marital status and nationality.
|
|
School career
|
Chronology of schools, institutions, universities, type of courses attended, diplomas passed, exam results, other diplomas obtained, assessments of study progress.
|
|
Professional qualification
|
Professional qualifications and training, special licenses (pilots, ...).
|
|
Company assets held by employees
|
Company cars, work tools, spare parts, other items held by the employee.
|
|
Immigration Status
|
Details about visa, work permit, residence or travel restrictions, special conditions linked to the right of residence.
|
|
Current job
|
Employer, job title, description of the job, degree, date of recruitment, place of work, specialization or type of company, working modalities and conditions, previous functions and previous experience with the current employer.
|
|
Wage
|
Payments and deductions, wages, commissions, bonuses, expenses, gratuities, benefits, loans, fees, deductions, pension deductions, union dues, payment methods, date of last pay increase.
|
|
Application
|
Date of employment, method of hiring, source of employment, references, details about the probationary period.
|
|
Professional experience
|
Professional interests, research interests, study interests, specialization topics, teaching experiences, counseling.
|
|
Employment contract
|
Date of departure, reasons for withdrawal, notice given, conditions for termination of the contract.
|
|
Professional activities
|
The nature of the activities, goods or services used or supplied by the data subject, business contacts.
|
|
Evaluation of the use of computer resources
|
Evaluation of the use of computer resources (Internet, e-mail, etc.)
|
|
Training costs
|
School fees paid and costs, sources of funding, payment methods, payment chronology
|
|
Organisation of work
|
Current responsibilities, projects, calculated hourly wage, working hours, hours worked.
|
|
Payment
|
Altitude, date...
|
|
Customer Management
|
Complaints, revocation, reminder data, user behaviour
|
|
Image recordings
|
Films, photographs, video recordings, digital photos.
|
|
Electronic
Credentials
|
IP addresses, cookies, connection times, electronic signature, browser used, device used, times to visit or use a web service, time of consent or consent, operating system, referrer URL
|
|
Financial identification data
|
Bank identification and bank account number, credit and debit card numbers, secret codes.
|
|
Enterprise Security
|
Passwords, security codes, and approval levels.
|
|
Accounts
|
Login data, passwords, username
|
|
Employee training
|
Details of the training needs required for the role and the training received, existing qualifications and required competencies.
|
|
Biometric
Credentials
|
Fingerprints, voice recognition, retinal imaging, recognition of the face, finger or hand shape, signature dynamics, ....
|
General information on the purpose and legal basis of the processing
|
|
04.01 Acceptance of an application
|
|
|
Purpose:
|
Acceptance of an application by e-mail, via an application form on the homepage, by post, via an applicant portal
|
|
Categories:
|
Professional Qualifications, Careers, Personal Details, Personal Identification Data, School Career
|
|
Data origin:
|
Collected from those affected
|
|
Legal bases:
|
2. Performance of contract (Art. 6 para. 1 lit. b) GDPR
|
|
Recipient categories:
|
Internal Department
|
|
| |
|
|
04.02 Management of Applicants (Applicant File)
|
|
|
Purpose:
|
Acquisition of new employees Filing of applications for effective support of applicants in the application process
|
|
Categories:
|
Professional Qualifications, Careers, Personal Details, Personal Identification Data, School Career
|
|
Data origin:
|
Collected from those affected
|
|
Legal bases:
|
2. Performance of contract (Art. 6 para. 1 lit. b) GDPR
|
|
Recipient categories:
|
Internal Department
|
|
|
04.03 Communication with the applicant
|
|
|
Purpose:
|
Carrying out the necessary communication with the applicant via telephone, e-mail or post, to arrange appointments, to communicate acceptances or rejections
|
|
Categories:
|
Personal Identification Information
|
|
Data origin:
|
Collected from those affected
|
|
Legal bases:
|
2. Performance of contract (Art. 6 para. 1 lit. b) GDPR
|
|
Recipient categories:
|
Internal Department
|
|
|
|
|
04.04 Interview/ Assessment of the applicant
|
|
|
Purpose:
|
Minutes of the interview with the applicant. Logging of relevant information for the eventual hiring.
|
|
Categories:
|
Application, immigration status, current job, salary, personal identification information, company assets held by employees
|
|
Data origin:
|
Collected from those affected
|
|
Legal bases:
|
4. Balancing in the case of legitimate interest Art. 6 para. 1 sentence 1 lit. f)
|
|
Recipient categories:
|
Internal Department
|
|
|
04.06 Keeping application documents on file
|
|
|
Purpose:
|
Recruitment of new employees: With the applicant's consent, the application will be kept on file for 1 year after the rejection in order to contact the applicant if necessary
|
|
Categories:
|
Professional Qualifications, Careers, Personal Details, Personal Identification Data, School Career
|
|
Data origin:
|
Collected from those affected
|
|
Legal bases:
|
3. Consent (Art. 6 para. 1 lit. a) GDPR
|
|
|
Recipient categories:
|
Internal Department
|
| |
|
|
04.07 Recruitment of the applicant
|
|
|
Purpose:
|
Acceptance of the applicant into the employing status
|
|
Categories:
|
Professional Qualifications, , Careers, Personal Details, Personal Identification Data, School Career
|
|
Data origin:
|
Collected from those affected
|
|
Legal bases:
|
1. Compliance with legal obligation (Art. 6 para. 1 lit. c) GDPR
|
|
Recipient categories:
|
Internal Department
|
|
11.03 Backups
|
|
|
Purpose:
|
In order to ensure the availability of data, data from clients and/or servers is backed up in the form of backups.
|
| |
|
Categories:
|
- Organisation of work
- Employment contract
- Training costs
- Accounts
- Professional activities
- Professional experience
- Professional qualification
- Application
- Evaluation of the use of computer resources
- Image recordings
- Electronic identification data
- Financial identification data
- Customer Management
- Wage
- Employee training
- Personal details
- Personal Identification Information
- Enterprise Security
- Payment
|
|
Data origin:
|
Collected from those affected
|
|
Legal bases:
|
4. Balancing in the case of legitimate interest Art. 6 para. 1 sentence 1 lit. f)
|
|
Recipient categories:
|
Internal Department
|
|
11.04 E-mail correspondence
|
|
|
Purpose:
|
Exchange of messages on internal work organization, communication with interested parties and customers, as well as order organization with suppliers
|
|
Categories:
|
Electronic Identification Data Personal Identification Data
|
|
Data origin:
|
Collected from those affected
|
|
Legal bases:
|
2. Performance of contract (Art. 6 para. 1 lit. b) GDPR
|
|
Recipient categories:
|
External Participants Internal Department
|
|
| |
|
|
11.08 Document Management System
|
|
|
Purpose:
|
Management of all documents created that concern the company
|
|
Categories:
|
Personal Identification Information
|
|
Data origin:
|
Collected from those affected
|
|
Legal bases:
|
2. Performance of contract (Art. 6 para. 1 lit. b) GDPR
|
|
Recipient categories:
|
Internal Department
|
|
|
11.12 Using a Cloud Solution
|
|
|
Purpose:
|
The cloud is used as a storage location for all files in the company.
|
|
Categories:
|
User Accounts, Personal Identification Information
|
|
Data origin:
|
Collected from those affected
|
|
Legal bases:
|
2. Performance of contract (Art. 6 para. 1 lit. b) GDPR
|
|
Recipient categories:
|
Cloud Provider Internal Department
|
|
|
12.11 Video surveillance of the company premises
|
|
|
Purpose:
|
Public as well as non-public places are under video surveillance for security reasons and for law enforcement.
|
|
Categories:
|
Image recordings, biometric identification data
|
|
Data origin:
|
Collected from those affected
|
|
Legal bases:
|
4. Balancing in the case of legitimate interest Art. 6 para. 1 sentence 1 lit. f)
|
|
Recipient categories:
|
-
|
|
|
12.12 Video surveillance of indoor premises
|
|
|
Purpose:
|
Public as well as non-public places are under video surveillance for security reasons and for law enforcement.
|
|
Categories:
|
Image recordings, biometric identification data
|
|
Data origin:
|
Collected from those affected
|
|
Legal bases:
|
4. Balancing in the case of legitimate interest Art. 6 para. 1 sentence 1 lit. f)
|
|
Recipient categories:
|
-
|
|
|
12.13 Video surveillance of entrances to company buildings or company premises from the outside
|
|
|
Purpose:
|
Public as well as non-public places are under video surveillance for security reasons and for law enforcement.
|
| |
|
Categories:
|
|
Image recordings, biometric identification data
|
|
Data origin:
|
|
Collected from those affected
|
|
Legal bases:
|
|
4. Balancing in the case of legitimate interest Art. 6 para. 1 sentence 1 lit. f)
|
|
Recipient categories:
|
-
|
|
Transfer to a third country
A transfer to a third country is not intended.
Duration of data storage
If necessary, we process and store your personal data for the duration of our business relationship or for the fulfilment of contractual purposes. This also includes, among other things, the initiation and execution of a contract.
In addition, we are subject to various retention and documentation obligations, which result from the German Commercial Code (HGB) and the German Fiscal Code (AO), among others. The retention or documentation periods prescribed there are two to ten years.
Finally, the storage period is also based on the statutory limitation periods, which can usually be three years, but in certain cases up to thirty years, e.g. according to §§ 195 et seq. of the German Civil Code (BGB).
Your rights
Every data subject has the right to information pursuant to Art. 15 GDPR, the right to rectification pursuant to Art. 16 GDPR, the right to erasure pursuant to Art. 17 GDPR, the right to restriction of processing pursuant to Art. 18 GDPR, the right to notification pursuant to Art. 19 GDPR and the right to data portability pursuant to Art. 20 GDPR.
In addition, you have the right to lodge a complaint with a data protection supervisory authority in accordance with Art. 77 GDPR if you believe that the processing of your personal data is not lawful. The right of appeal exists without prejudice to any other administrative or judicial remedy.
If the processing of data is based on your consent, you are entitled to revoke your consent to the use of your personal data at any time in accordance with Art. 7 GDPR. Please note that the revocation only takes effect for the future. Processing that took place before the revocation is not affected. Please also note that we may need to retain certain data for a certain period of time in order to comply with legal requirements.
To protect your rights, you can contact us using the contact details provided.
Right to object
Insofar as the processing of your personal data is carried out in accordance with Art. 6 (1) (f) GDPR to safeguard legitimate interests, you have the right to object to the processing of this data at any time for reasons arising from your particular situation in accordance with Art. 21 GDPR. We will then no longer process this personal data unless we can demonstrate compelling legitimate grounds for the processing. These must outweigh your interests, rights and freedoms, or the processing must serve the establishment, exercise or defence of legal claims.
Necessity of providing personal data
The provision of personal data for the purpose of deciding on the conclusion of a contract, the fulfilment of a contract or for the implementation of pre-contractual measures is voluntary. However, we can only make a decision within the framework of contractual measures if you provide such personal data that is necessary for the conclusion of the contract, the performance of the contract or pre-contractual measures.
Automated decision-making
For the establishment, fulfilment or implementation of the business relationship as well as for pre-contractual measures, we do not use fully automated decision-making in accordance with Art. 22 GDPR. If we use these procedures in individual cases, we will inform you separately or Obtain your consent, where required by law.