Privacy policy
Thank you for visiting our website https://www.rud-he.de/. This privacy policy informs users about the type, scope and purpose of the processing of personal data within this website and the associated websites, mobile applications and external online presences, such as social media profiles.
1. controller
RUD H&E GmbH
Efeuweg 4, 38104 Braunschweig, Germany
RUD H&EGmbH
Lange Straße 69
37339 Breitenworbis
E-mail : vertrieb@rud-he.de
Website: https://www.rud-he.de/
You can reach our data protection officer at datenschutzbw@rud-he.de
2 Processing of personal data
2.1 What is personal data?
Personal data means any information relating to an identified or identifiable natural person; an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, Art. 4 para. 1 GDPR.
2.2 Legal bases
The processing of personal data on this website is carried out in compliance with the relevant data protection regulations (in particular GDPR and BDSG) and on the basis of legal authorisation.
Personal data is only processed
- with the consent of the user pursuant to Art. 6 para. 1 sentence 1 lit. a GDPR,
- for the fulfilment of a contract or for the implementation of pre-contractual measures pursuant to Art. 6 para. 1 sentence 1 lit. b GDPR,
- for the fulfilment of legal obligations pursuant to Art. 6 para. 1 sentence 1 lit. c GDPR or
- to safeguard the legitimate interests of the controller pursuant to Art. 6 para. 1 sentence 1 lit. f GDPR.
2.3 Forwarding of data
If personal data is passed on to other persons or companies in the course of processing, this is done in compliance with the legal requirements and after the conclusion of corresponding contracts or agreements.
2.4 Data processing in third countries
If it is absolutely necessary to transfer personal data to a so-called "third country" (i.e. a country outside the European Union or the European Economic Area), this will only take place if there is a recognised level of data protection or on the basis of special guarantees, certifications or binding internal data protection regulations within the meaning of Art. 44 - 49 GDPR.
2.5 Storage period
Unless otherwise stated in this privacy policy, personal data will be deleted as soon as the purpose of processing ceases to apply or the consent on which the processing is based has been revoked. If statutory retention obligations or limitation periods prevent deletion, the personal data concerned may only be processed for commercial or tax law purposes or for the assertion, exercise or defence of legal claims.
2.6 Rights of data subjects
The user has the right to
- confirmation as to whether their own personal data is being processed and to information about this data as well as to further information and a copy of this data, Art. 15 GDPR
- Completion of their own personal data or correction of incorrect personal data, Art. 16 GDPR
- Erasure of your own personal data if there is a reason for erasure stated therein, Art. 17 GDPR
- Restriction of the processing of your own personal data if there is a reason stated therein, Art. 18 GDPR
- Transfer of your own personal data to another controller, Art. 20 GDPR
- Complaint to a supervisory authority if they believe that the processing of their personal data violates applicable laws, Art. 77 GDPR
Responsible supervisory authority:
Thüringer Landesbeauftragter für den Datenschutz und die Informationsfreiheit (TLFD)
Postfach 90 04 55
99107 Erfurt
Phone: 03 61/37 71 900
Fax: 03 61/37 71 904
Email: poststelle@datenschutz.thueringen.de
The user has the right to withdraw consent given at any time with effect for the future, Art. 7 para. 3 GDPR.
The user has the right to object at any time to the future processing of data concerning him/her in accordance with Art. 21 GDPR. The objection may be made in particular against processing for direct marketing purposes.
3. processing of personal data on this website
As a rule, users can use the website without providing personal information. This does not apply to information that is automatically collected each time the website is accessed (so-called server log files). This includes
- File name of the requested file
- End device used (mobile device or PC/laptop)
- Browser type / version
- Javascript activation
- cookie activation
- Referring URL
- IP address
- Duration of access
- Number of pages accessed
- Click path
The legal basis for the processing of personal data in this context is Art. 6 para. 1 sentence 1 lit. f GDPR, as the possibility of technical administration and ensuring the security of the website is in the legitimate interest of the controller. The purposes of processing are to enable the use of the website (connection establishment), system security, technical administration of the network infrastructure and optimisation of the website. The stored data is deleted after seven days unless there is a justified suspicion of unlawful use based on concrete evidence that makes further examination necessary. The controller is not in a position to identify users as data subjects on the basis of the stored information.
It may be necessary to provide personal information in exceptional cases for individual functionalities of the website. Further information on this can be found under "Individual functionalities".
4. cookies
The website uses cookies. Cookies are small files that are stored on the user's end device (PC, smartphone, etc.).
users can influence the use of cookies. Most browsers have an option that restricts or completely prevents the storage of cookies. Users can also delete cookies in their browser's security settings at any time. Further information on this can be found at the Federal Office for Information Security.
Necessary cookies
These cookies are absolutely essential for websites and their functions to work properly. Without these cookies, certain functionalities cannot be provided. The data processed by necessary cookies are required for the purposes mentioned to safeguard the legitimate interests of the controller pursuant to Art. 6 para. 1 sentence 1 lit. f GDPR. The controller currently uses the following necessary cookies for the following purposes
| Name of cookie | Purpose and function of the cookies | Expiry date |
|---|---|---|
| fontsLoaded | Tracks special fonts used on the website for internal analyses. The cookie does not register any user data. | Session |
5. individual functionalities
The functionalities used on the website are operated on the basis of the user's consent pursuant to Art. 6 para. 1 sentence 1 lit. a GDPR or on the basis of the legitimate interest of the controller pursuant to Art. 6 para. 1 sentence 1 lit. f GDPR. The legitimate interest of the controller lies in ensuring the appropriate design and continuous optimisation of the website. The purpose of data processing and categories of personal data are described in the context of the respective functionality.
5.1 Google WebFonts (local hosting)
The website uses Google Web Fonts from Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland (hereinafter referred to as "Google") for the standardised display of fonts. Google Web Fonts are installed locally. A connection to Google servers is not established. Further information on Google Web Fonts can be found at https://developers.google.com/fonts/faq and at https://policies.google.com/privacy?hl=de.
5.2 Conference calls, online meetings, video conferences and/or webinars
For telephone conferences, online meetings, video conferences and/or webinars, the controller uses "Microsoft Teams", a service of Microsoft Ireland, South County Business Park, One Microsoft Place, Carmanhall and Leopardstown, Dublin, D18 P521, Ireland (hereinafter referred to as "Microsoft").
The processing of personal data is based on the legitimate interest of the controller pursuant to Art. 6 para. 1 lit. f GDPR in the effective organisation of telephone conferences, online meetings, video conferences and/or webinars. Insofar as personal data of employees of the controller are processed, Art. 6 para. 1 lit. b, f GDPR is the legal basis for data processing.
Telephone conferences, online meetings, video conferences and/or webinars can be participated in via the respective app as well as via the respective browser-based version. We would like to point out that the use of the browser-based versions is generally more data protection-friendly than the use of the app-based versions. The scope of the personal data processed depends on the information you provide before or when participating in a conference call, online meeting, video conference and/or webinar.
The following personal data may be processed:
- User details: display name, email address (optional), profile picture (optional), preferred language
- Meeting metadata: Title, date, time, location, meeting details if applicable, meeting ID, device/hardware information
- Text, audio and video data: Users may have the opportunity to use the chat function during conference calls, online meetings, video conferences and/or webinars. In this respect, the text entries made by the user are processed in order to display and, if necessary, log them. In order to enable the display of video and the playback of audio, the data from the microphone of the end device and from any video camera of the end device are processed accordingly for the duration of the meeting. Users can switch off or mute the camera or microphone themselves at any time.
Microsoft Teams is part of Microsoft Office 365. If users have a Microsoft Office 365 account and are logged into it, personal data may be stored by Microsoft as part of conference calls, online meetings, video conferences and/or webinars. The scope and duration of storage depends on the respective settings in the user account, over which the controller has no influence.
Conference calls, online meetings, video conferences and/or webinars are not recorded. Chat content is not logged.
An appropriate level of data protection is guaranteed on the one hand by the conclusion of the so-called EU standard contractual clauses. As additional protective measures, we have configured the respective applications as strictly as possible from a data protection perspective. The controller would like to point out that Microsoft Teams is part of Microsoft Office 365.
Further information on data protection and data security can be found at
https://privacy.microsoft.com/de-de/privacystatement
https://docs.microsoft.com/de-de/microsoftteams/teams-privacy
5.3 Making contact
When contacting the controller (e.g. by email or using the contact form), the information provided by the requesting user is processed insofar as this is necessary to respond to the contact request and any measures requested.
The legal basis for the processing of personal data in this context is Art. 6 para. 1 lit. f GDPR, as it is in the legitimate interest of the controller to answer enquiries.
The data provided by the enquiring user when contacting us will only be passed on with the user's consent within the meaning of Art. 6 para. 1 lit. a GDPR.
6. further data processing
6.1 Contractual relationships
The processing of personal master data, contract data and payment data is required to establish and/or execute contractual relationships with customers. The legal basis for the processing is Art. 6 para. 1 sentence 1 lit. b GDPR.
The controller processes customer and prospective customer data for evaluation and marketing purposes. The legal basis for the processing is Art. 6 para. 1 sentence 1 lit. f GDPR. The processing serves the legitimate interest of the controller to further develop the range of services and to provide targeted information about this.
Further processing of personal data only takes place on the basis of consent within the meaning of Art. 6 para. 1 sentence 1 lit. a GDPR or in the context of the fulfilment of legal obligations within the meaning of Art. 6 para. 1 sentence 1 lit. c GDPR.
6.2 Employment relationships
The controller offers applicants the opportunity to apply for vacancies. Job advertisements are published via the Stepstone job portal(https://www.stepstone.de) and via the job portal of the employment agency(https://www.arbeitsagentur.de).
When publishing job adverts via the Stepstone job portal, applicants have the opportunity to apply directly via Stepstone, The Stepstone Group Deutschland GmbH, Völklinger Straße 1, 40219 Düsseldorf, Germany (hereinafter referred to as "Stepstone"). To do so, the applicant must first register with Stepstone. The legal basis for the processing of personal data is the user contract concluded between Stepstone and the applicant within the meaning of Art. 6 para. 1 sentence 1 lit. b GDPR, over which the controller has no influence. The general terms and conditions of Stepstone are available at https://www.stepstone.de/e-recruiting/rechtliches/agb-stellenanzeigen. Stepstone's privacy policy is available at https://www.stepstone.de/e-recruiting/rechtliches/datenschutzerklarung.
When publishing job adverts via the job portal of the employment agency, applicants have the option of applying directly to the controller by email or post. Alternatively, applicants can write a message to the person responsible via the job portal of the employment agency. To do this, the applicant must first register for the online services of the Federal Employment Agency. The legal basis for the processing of personal data is the user contract concluded between the Federal Employment Agency and the applicant within the meaning of Art. 6 para. 1 sentence 1 lit. b GDPR, over which the controller has no influence. The terms of use of the Federal Employment Agency are available at https://www.arbeitsagentur.de/nutzungsbedingungen. The Federal Employment Agency's privacy policy is available at https://www.arbeitsagentur.de/datenschutzerklaerung.
Communication by email is always unencrypted. There is therefore a risk that transmitted data can be viewed by third parties. In order to avoid risks and to protect personal data in the best possible way, we recommend that applicants send their application documents by post.
As part of the application process, personal data relating to the specific application is processed, e.g. general personal data, information on education, vocational training and further training as well as other information provided by applicants.
The controller processes personal data for the purpose of carrying out the application process and handling the employment relationship, if such a relationship is established, on the basis of Art. 6 para. 1 lit. b GDPR (if § 26 para. 1 sentence 1 BDSG no longer applies) and, if applicable, Art. 9 para. 2 lit. b and h GDPR (if health data are affected). Furthermore, personal data may be processed if this is necessary for the fulfilment of legal obligations (Art. 6 para. 1 lit. c GDPR) or for the defence of legal claims asserted against the controller (Art. 6 para. 1 lit. f GDPR). The legitimate interest is, for example, a burden of proof in proceedings under the General Equal Treatment Act (AGG).
Personal data is stored for the aforementioned purposes for as long as is necessary for the fulfilment of these purposes. For the purpose of defence against legal claims asserted against the controller in the application process, personal data will be stored for a maximum of 6 months and then deleted.
The provision of personal data as part of the application process is not required by law or contract. Applicants are therefore not obliged to provide any information. However, the provision of personal data is necessary for the decision on an application or the conclusion of a contract in relation to an employment relationship. If applicants do not provide personal data, the controller cannot make a decision on the establishment of an employment relationship. It is recommended that you only provide the personal data that is required in this context as part of the application.
In individual cases, the application process may also be supported by a qualified department of a company belonging to the Group.
7 Security of processing
The website uses the SSL (Secure Socket Layer) method in conjunction with the highest level of encryption supported by the browser used. Whether an individual website of the website is transmitted in encrypted form is indicated in the address bar of the browser by the prefix https:// and/or the closed lock symbol.
The controller uses technical and organisational security measures to protect the personal data it manages against accidental or intentional manipulation, loss, destruction or access by unauthorised persons. The security measures are continuously improved in line with technological developments.
8 Validity and up-to-dateness of the privacy policy
Due to ongoing legal and technical developments, the controller reserves the right to update this privacy policy at any time.