Privacy Policy

Downloads & Links

We appreciate your interest in our company. Data protection and data security are a top priority for us. Below, we would like to provide you with comprehensive information about how we process personal data within our company and on our website.

We are

ENERPARC AG
Kirchenpauerstraße 26
20457 Hamburg
Tel.: +49 (0)40 75 66 449-0
Email: mail@enerparc.com
represented by the Executive Board: Christoph Koeppen, Frank Müllejans, Stefan Müller.

We have appointed an external Data Protection Officer. This person can be reached at the above address with the note “personal – confidential for the Data Protection Officer” as well as at datenschutz@enerparc.com.

Provided certain conditions are met, you have the right to 

  • access your data, to have incorrect data corrected,
  • to have your data deleted if there is no longer a reason to retain it,
  • to restrict processing,
  • data portability, to object to processing based on our legitimate interest (Article 6(1)(f) of the GDPR),
  • to withdraw consent that has been given with effect for the future, and
  • to lodge a complaint about us with the competent supervisory authority.

Of course, these rights are subject to conditions set forth in the relevant laws, in particular the General Data Protection Regulation (GDPR).

If we transfer your data to countries outside the European Union (third countries), we require additional safeguards as provided for in Articles 44 et seq. of the GDPR. These include, in particular, 

  • adequacy decisions, in which the European Commission has determined that a country or sector has an adequate level of data protection (Article 45 of the GDPR),
  • standard contractual clauses, through which data recipients in third countries contractually commit to maintaining an adequate level of data protection (Article 46 of the GDPR),
  • Binding internal data protection rules that have been reviewed by EU supervisory authorities and through which data recipients from third countries commit to maintaining an adequate level of data protection (Article 47 of the GDPR),
  • Declarations of consent through which you accept, on a case-by-case basis, that your data will be transferred to a third country (Article 49(1)(a) of the GDPR). Any risk notices can be found in the glossary.

We would like to provide the following additional information: 

  • When we process your data, no automated decision-making—and in particular, no profiling—takes place.
  • We are only legally obligated to process your data if we expressly indicate this in the following privacy policy.

Contact Us

First, we collect your data to establish initial contact. In this context, it is possible that we will contact you first, for example, as part of our recruitment of shepherds and biologists. It is also possible that you will contact us first. In any case, we process all data that we have either researched in advance and/or that you voluntarily provide to us. This often includes your contact information (name, email address, mailing address, phone number) as well as communication data (e.g., description of the conversation, conversation notes, form entries). Based on this, we review your proposal and store the relevant data. The purpose of this processing is to initiate or establish a contract. The legal basis for this is Article 6(1)(b) of the GDPR.

Video Conferences

In some cases, you may communicate with us via video conference. In doing so, we process the resulting image and audio data as well as any transcripts that may be created. The purpose of this processing is either to negotiate a contract with you or, at a later stage, to fulfill it. The legal basis is Article 6(1)(b) of the GDPR.  

Recordings are only made if we suggest it and you consent. To fulfill a legal obligation (Article 7(1) of the GDPR), we first store the information regarding whether you have consented. The legal basis for this is Article 6(1)(c) of the GDPR. We then record the conversation and store the resulting video and audio data to document the conversation. The legal basis for this is Article 6(1)(a) of the GDPR. The prohibition under Article 9(1) of the GDPR does not preclude this, as the exception under Article 9(2)(a) of the GDPR applies.

Contract Performance

If a contract is actually concluded between us, we communicate with you, make payments, etc., and in doing so process communication and billing data (e.g., for the delivery of services and responding to inquiries) in order to fulfill the contract. The purpose of this processing is the performance of the contract. The legal basis for this is Article 6(1)(b) of the GDPR.

Notification of Changes to Data Processing

If we ever change the way we process your data (e.g., by using new tools), we will inform you of the changes, e.g., via email. As a rule, we will send you updated privacy information. The processing is intended to fulfill a legal obligation (Articles 12–14 of the GDPR). The legal basis for this is Article 6(1)(c) of the GDPR.

Data Processing When Exercising Rights

If you exercise your rights under the GDPR or other legal provisions, we process your data to review these claims and, if necessary, fulfill them. The purpose of this processing is to fulfill a legal obligation. The legal basis for this is Article 6(1)(c) of the GDPR in conjunction with the respective legal provision from which your right or claim arises.

Involvement of a Tax Advisory Firm

We transmit tax-related data concerning you (e.g., quotes, order confirmations, contracts, invoices, bank statements, etc.) to an external tax consulting firm. In doing so, we process your name as well as all data derived from invoices and payment receipts. We therefore seek support with accounting and other tax-related matters. The legal basis for this is Article 6(1)(f) of the GDPR, whereby our legitimate interest arises from the stated purpose. To the extent that the external tax consulting firm processes this data, this does not constitute commissioned processing (see DSK Brief 13), but rather a data transfer justified by Article 6(1)(f) of the GDPR.

Video recordings on the premises of the solar parks

Our solar parks are under video surveillance, and the video surveillance data (image data, recording period, recording location) is processed to protect our right of access, our property, and our possessions, as well as to fulfill legal obligations (Article 32 GDPR: access control, Section 8a of the BSI Act: special security measures). Furthermore, still images are recorded several times a day to measure and statistically evaluate any environmental impacts (e.g., hail, snowfall). To the extent that the processing serves to protect our right of access, our property, and our possessions, the legal basis is Article 6(1)(f) of the GDPR, whereby the legitimate interest arises from the aforementioned purposes. To the extent that the processing serves to fulfill legal obligations, Article 6(1)(c) of the GDPR is the legal basis. To the extent that the processing serves the measurement and evaluation of any environmental impacts, Article 6(1)(f) of the GDPR is the legal basis, whereby the legitimate interest arises from the aforementioned purpose.

Data logging when using WebGIS and/or QGIS

If you use the tools mentioned in the heading as part of your contractual relationship with us, we collect the following data: 

  • for WebGIS (username, number_of_logins, last_login) 
  • for QGIS (ld, plugin, created_by - username, created_at, last_update)

The processing serves only for internal monitoring (usage statistics, troubleshooting). The legal basis is Article 6(1)(f) of the GDPR, whereby the legitimate interest arises from the aforementioned purpose.

Data Retention/Storage Period

We retain your data both during and after the end of the contract. Here we inform you how long the data is stored:

  • We retain internal records (e.g., annual financial statements, accounting documents) for ten years. This period begins on December 31 of the calendar year in which the respective document was created. We are legally obligated to do so (Section 147 AO, Section 257 HGB), and the legal basis is Article 6(1)(c) of the GDPR in conjunction with the respective statutory provision from which your right or claim arises.
  • We retain business correspondence (e.g., customer letters) and other tax-related documents for six years. This period begins on December 31 of the calendar year in which the respective document was created. We are legally obligated to do so (Section 147 AO, Section 257 HGB), and the legal basis is Article 6(1)(c) of the GDPR in conjunction with the respective statutory provision from which your right or claim arises.
  • When you exercise your rights under the GDPR, communication data is generated (correspondence via email, mail, etc.). We retain this data for three years. This period begins on December 31 of the calendar year in which we responded to your request. In doing so, we are pursuing our own legitimate interests. This is because we want to be able to prove, in the event of a dispute, that we have handled your claims correctly. The legal basis is Article 6(1)(f) of the GDPR. The three-year period is based on the statute of limitations for claims for damages (Sections 195, 199(1) of the German Civil Code (BGB)) and, additionally, the statute of limitations provisions under administrative offense law (Section 31(2)(1) of the German Administrative Offenses Act (OWiG) in conjunction with Article 83 of the GDPR).
  • If you assert other, non-GDPR rights, communication data is also generated, which we retain for three years. This period begins on December 31 of the calendar year in which we responded to your request. In doing so, we are pursuing our own legitimate interests. This is because we want to be able to prove, in the event of a dispute, that we have handled your claims correctly. The legal basis is Article 6(1)(f) of the GDPR. The three-year period is based on the statute of limitations for claims for damages (Sections 195, 199(1) of the German Civil Code (BGB)).
  • If you consent to data processing,
    we store the information that you have consented for three years. This period begins as soon as you withdraw your consent or the associated purpose ceases to exist, whichever occurs first. In doing so, we are pursuing our own legitimate interests. This is because we want to be able to prove in the event of a dispute that we have handled your claims correctly. The legal basis is Article 6(1)(f) of the GDPR. The three-year period is governed by the statute of limitations provisions for claims for damages (Sections 195, 199(1) of the German Civil Code (BGB)) and, additionally, the statute of limitations provisions under administrative offense law (Section 31(2)(1) of the German Administrative Offenses Act (OWiG) in conjunction with Article 83 of the GDPR).
    - We store the data we process based on your consent until you revoke your consent. The purpose is derived from the respective declaration of consent, and the legal basis for this is Article 6(1)(a) of the GDPR. 
  • Video recordings on the premises of the solar parks are generally retained for only 48 hours. The legal basis is Article 6(1), first sentence, lit. f of the GDPR, whereby the legitimate interest arises from the aforementioned purposes (protection of our right of access, our property, and our possessions). If these purposes are compromised (e.g., trespassing, theft, property damage), we retain the data for as long as necessary to pursue our rights (e.g., claims for damages), but delete it no later than upon final clarification of the facts. 
  • Still images derived from the video recordings and created for the measurement and evaluation of any environmental impacts are retained for a maximum of 5 years, with the period beginning on December 31 of the calendar year in which the recordings were made. The legal basis is Article 6(1)(f) of the GDPR, whereby the legitimate interest arises from the aforementioned purpose.
  • Monitoring data generated during the use of WebGIS (username, number_of_logins, last_login) and/or QGIS (ld, plugin, created_by - username, created_at, last_update) is deleted 12 months after the data is collected. The legal basis for retention is Article 6(1)(f) of the GDPR, whereby the legitimate interest arises from the fact that access to the data may be necessary within one year to resolve current issues.

Deletion of Data

As soon as the aforementioned retention periods end, we delete your data. In doing so, we fulfill a legal obligation (Article 5(1)(a), (e) GDPR). The legal basis is Article 6(1), first sentence, lit. c GDPR.

Recipients

The following recipients and other external parties process your data:

Recipients within the European Union: Within the European Union, your data is processed by companies (recipients) in the following categories:

  • Backup tool providers
  • Software hosting companies,
  • providers of video conferencing systems,
  • Law firms, tax firms, and auditing firms 
  • Project management tools,
  • Providers of whistleblower platforms,
  • Providers of accounting solutions
  • Providers of Microsoft assistant tools
  • Providers of translation tools

Recipients outside the European Union: Outside the European Union, your data is processed by the following specific companies (recipients):

  • Microsoft: Various applications from Microsoft Corporation (USA) are used, which has been commissioned in accordance with Article 28 of the GDPR, namely: Microsoft 365 Cloud, Microsoft Teams (project management tool), Microsoft Teams (video conferencing tool), Microsoft Bookings, Microsoft Forms, SharePoint. A transfer of data to a third country (in this case, the USA), which cannot be ruled out, is justified in accordance with Article 45 of the GDPR.
  • New Relic: The website monitoring tool “New Relic” from New Relic, Inc. (USA) is used; New Relic, Inc. has been commissioned in accordance with Article 28 of the GDPR. A transfer of data to a third country (in this case, the USA), which cannot be ruled out, is justified in accordance with Article 45 of the GDPR.
  • Lacework: The IT security tool “Lacework” from Lacework, Inc. (USA) is used. A transfer of data to a third country (in this case, the USA), which cannot be ruled out, is justified in accordance with Article 46 of the GDPR.
  • ShareFile: The IT tool “ShareFile” from Citrix Systems Inc. (USA) is used, which has been commissioned in accordance with Article 28 of the GDPR. A data transfer to a third country (in this case, the USA) that cannot be ruled out is justified in accordance with Article 46 of the GDPR.
  • Monday.com: The collaboration tool “Monday.com” from Monday.com Ltd. (Israel) is used. A data transfer to a third country (in this case, Israel) that cannot be ruled out is justified in accordance with Article 45 of the GDPR.
  • Atlassian: The project management tool from Atlassian Pty Ltd (Australia) is used, which has been commissioned in accordance with Article 28 of the GDPR. A data transfer to a third country (in this case, Australia) that cannot be ruled out is justified in accordance with Article 46 of the GDPR.
  • Autodesk: The “Autodesk” project management tool from Autodesk, Inc. (USA) is used; Autodesk, Inc. has been appointed as a processor in accordance with Article 28 of the GDPR. A transfer of data to a third country (in this case, the USA), which cannot be ruled out, is justified under Article 46 of the GDPR for employee data and under Article 45 of the GDPR for all other data.

Special Considerations Regarding Responsibilities  

We are always looking for property owners on whose land we can build solar parks and similar projects. To this end, we contact property owners. In some cases, we cooperate with external companies. These companies research contact information and also reach out to property owners on our behalf.  

If you have been contacted in this way, please note that these companies and we have entered into a contractual agreement to jointly process your data. These agreements stipulate that you may contact both us and the aforementioned companies if you wish to exercise your rights. Furthermore, we have agreed that both we and our contractors will independently ensure the lawfulness and security of the processing. You can easily find the identity of the company with which we are jointly responsible (Article 26 of the GDPR) in the letter and/or other information you receive from the company that contacts you.

Contact

First, we collect your data to establish initial contact. We may research the data ourselves or have it researched at cadastral or land registry offices (see “Special Features Regarding Responsibilities”). In doing so, we receive and process your name, your address, and information regarding which property you own. The purpose of the processing is that we may wish to negotiate a lease agreement with you. The legal basis for the processing depends on the state in which your property is located.

The following laws may apply:

  • Sections 13 et seq. of the Hamburg Surveying Act
  • Section 5(2) of the Lower Saxony Surveying Act
  • § 10 Law on State Surveying and the Real Estate Cadastre of Bremen
  • § 13(3) of the Schleswig-Holstein State Surveying and Real Estate Cadastre Act
  • Section 33(2) of the Law on Official Geoinformation and Surveying in Mecklenburg-Western Pomerania
  • Section 10(1) of the Law on Official Surveying in the State of Brandenburg
  • Section 17(1) of the Law on Surveying in Berlin
  • Section 13(1) of the Saxony-Anhalt Surveying and Geoinformation Act
  • Section 14(2) of the Saxon Surveying Act
  • Section 18(2) of the Thuringian Surveying and Geoinformation Act
  • Section 16(2) of the Hessian Act on the Real Estate Cadastre and State Surveying
  • Article 11(1) of the Law on State Surveying and the Real Estate Cadastre in Bavaria
  • Section 2(3) of the Surveying Act for Baden-Württemberg
  • Section 10(1) of the Saarland Act on State Surveying and the Real Estate Cadastre
  • Section 13(2) of the Rhineland-Palatinate State Law on Official Surveying
  • Section 14(2) of the North Rhine-Westphalia State Surveying and Real Estate Cadastre Act

In any case, and provided that your property is located outside of Germany, the processing is based on Article 6(1)(f) of the GDPR, whereby our legitimate interest arises from your foreseeable interest in a lease agreement.

Contract Performance

Should a lease agreement actually be concluded between us, we will communicate with you, make payments, etc., and in doing so process communication and billing data (e.g., for the delivery of services and responding to inquiries) in order to fulfill the contract. The purpose of this processing is the performance of the contract. The legal basis for this is Article 6(1)(b) of the GDPR.

Cases of corporate reorganization

If we ever sell the companies involved in the contracts by way of an asset deal, all of your contract data will be transferred to the new company. The legal basis is Article 6(1)(f) of the GDPR, whereby the legitimate interest arises from the fact that you have an interest in the continuation of the contract. In the case of a share deal or merger, no further legal basis is required, as no transfer of data takes place.

Proof of property availability to the grid operator

When applying for a grid connection, we are required to provide the respective grid operator with proof that we have economic control over the property in question. For this purpose, we provide the grid operator with extracts or copies of the lease agreements or corresponding evidence that specifically enable the grid operator to verify the availability of the property. In doing so, the grid operator generally receives the name and address of the property owner as well as information regarding which property is involved. The legal basis for this processing is Article 6(1)(f) of the GDPR. Our legitimate interest stems from the fact that the network operator is obligated to properly conduct the network connection procedure and must decide, based on objective criteria, whether and how a network connection can be established. This includes, in particular, verifying whether we, as the applicant, actually have access to the property. The disclosure of the relevant information is necessary to properly conduct the procedure and to achieve a legally compliant grid connection.

Notification of Changes to Data Processing

If we ever change the way we process your data (e.g., by using new tools), we will inform you of the changes, e.g., via email. As a rule, we will send you updated privacy information. The processing is intended to fulfill a legal obligation (Articles 12 through 14 of the GDPR). The legal basis for this is Article 6(1)(c) of the GDPR.

Data Processing When Exercising Rights

If you exercise your rights under the GDPR or other legal provisions, we process your data to review these claims and, if necessary, fulfill them. The purpose of this processing is to fulfill a legal obligation. The legal basis for this is Article 6(1)(c) of the GDPR in conjunction with the respective legal provision from which your right or claim arises.

Data Retention/Storage Period

We retain your data both during and after the end of the contract. Here we inform you how long the data is stored:

  • We retain internal records (e.g., annual financial statements, accounting documents) for ten years. This period begins on December 31 of the calendar year in which the respective document was created. We are legally obligated to do so (Section 147 AO, Section 257 HGB), and the legal basis is Article 6(1)(c) of the GDPR in conjunction with the relevant legal provision from which your right or claim arises.
  • We retain business correspondence (e.g., customer letters) and other tax-related documents for six years. This period begins on December 31 of the calendar year in which the respective document was created. We are legally obligated to do so (Section 147 AO, Section 257 HGB), and the legal basis is Article 6(1)(c) of the GDPR in conjunction with the respective statutory provision from which your right or claim arises.
  • When you exercise your rights under the GDPR, communication data is generated (correspondence via email, mail, etc.). We retain this data for three years. This period begins on December 31 of the calendar year in which we responded to your request. In doing so, we are safeguarding our own legitimate interests. This is because, in the event of a dispute, we want to be able to prove that we have handled your claims correctly. The legal basis is Article 6(1)(f) of the GDPR. The three-year period is based on the statute of limitations for claims for damages (Sections 195, 199(1) of the German Civil Code (BGB)) and, additionally, the statute of limitations provisions under administrative offense law (Section 31(2)(1) of the German Administrative Offenses Act (OWiG) in conjunction with Article 83 of the GDPR).
  • If you assert other, non-GDPR rights, communication data is also generated, which we retain for three years. This period begins on December 31 of the calendar year in which we responded to your request. In doing so, we are pursuing our own legitimate interests. This is because, in the event of a dispute, we want to be able to prove that we have handled your claims correctly. The legal basis is Article 6(1)(f) of the GDPR. The three-year period is based on the statute of limitations for claims for damages (Sections 195, 199(1) of the German Civil Code (BGB)).

  • If you consent to data processing, we will store the information that you have consented for three years. This period begins as soon as you withdraw your consent or the associated purpose ceases to exist, whichever occurs first. In doing so, we are pursuing our own legitimate interests. This is because we want to be able to prove in the event of a dispute that we have handled your claims correctly. The legal basis is Article 6(1)(f) of the GDPR. The three-year period is based on the statute of limitations for claims for damages (Sections 195, 199(1) of the German Civil Code (BGB)) and, in addition, the statute of limitations provisions under administrative offense law (Section 31(2)(1) of the German Administrative Offenses Act (OWiG) in conjunction with Article 83 of the GDPR).
    - We store the data we process based on your consent until you revoke your consent. The purpose is derived from the respective declaration of consent, and the legal basis for this is Article 6(1)(a) of the GDPR.

     

Deletion of Data

As soon as the aforementioned retention periods end, we delete your data. In doing so, we fulfill a legal obligation (Article 5(1)(a), (e) GDPR). The legal basis is Article 6(1), first sentence, (c) GDPR.

Recipients

The following recipients and other external parties process your data:

Recipients within the European Union: Within the European Union, your data is processed by companies (recipients) in the following categories:

  • Backup tool providers
  • Software hosting companies,
  • providers of video conferencing systems,
  • Law firms, tax firms, and auditing firms 
  • Project management tools,
  • Providers of whistleblower platforms,
  • Providers of accounting solutions
  • Providers of Microsoft assistant tools
  • Providers of translation tools
  • Responsible network operators

     

Recipients outside the European Union: Outside the European Union, your data is processed by the following specific companies (recipients):

  • Microsoft: Various applications from Microsoft Corporation (USA) are used, which has been commissioned in accordance with Article 28 of the GDPR, namely: Microsoft 365 Cloud, Microsoft Teams (project management tool), Microsoft Teams (video conferencing tool), Microsoft Bookings, Microsoft Forms, SharePoint. A transfer of data to a third country (in this case, the USA), which cannot be ruled out, is justified in accordance with Article 45 of the GDPR.
  • New Relic: The website monitoring tool “New Relic” from New Relic, Inc. (USA) is used; this company has been commissioned in accordance with Article 28 of the GDPR. A transfer of data to a third country (in this case, the USA), which cannot be ruled out, is justified in accordance with Article 45 of the GDPR.
  • Lacework: The IT security tool “Lacework” from Lacework, Inc. (USA) is used. A data transfer to a third country (in this case, the USA) that cannot be ruled out is justified in accordance with Article 46 of the GDPR.
  • ShareFile: The IT tool “ShareFile” from Citrix Systems Inc. (USA) is used, which has been commissioned in accordance with Article 28 of the GDPR. A data transfer to a third country (in this case, the USA) that cannot be ruled out is justified in accordance with Article 46 of the GDPR.
  • Monday.com: The collaboration tool “Monday.com” from Monday.com Ltd. (Israel) is used. A data transfer to a third country (in this case, Israel) that cannot be ruled out is justified in accordance with Article 45 of the GDPR.
  • Atlassian: The project management tool from Atlassian Pty Ltd (Australia) is used, which has been commissioned in accordance with Article 28 of the GDPR. A data transfer to a third country (in this case, Australia) that cannot be ruled out is justified in accordance with Article 46 of the GDPR.
  • Autodesk: The “Autodesk” project management tool from Autodesk, Inc. (USA) is used; Autodesk, Inc. has been appointed as a processor in accordance with Article 28 of the GDPR. A transfer of data to a third country (in this case, the USA), which cannot be ruled out, is justified under Article 46 of the GDPR for employee data and under Article 45 of the GDPR for all other data.

Special Provisions Regarding Responsibilities

To the extent that we maintain corporate pages on social media/networks, we would like to point out that 

  • to the extent that we analyze your use of our company page, we and the respective provider are jointly responsible under data protection law in accordance with Article 26 of the GDPR. 
  • we have commissioned the providers in all other cases pursuant to Article 28 of the GDPR.

Presentation of the Website

You have the option to use our website for informational purposes only. This means that you simply visit the site without clicking on anything or entering any information. Even then, we process the following data from you so that the website can be displayed in your browser at all:  

  • IP address, 
  • Date and time of the request, 
  • Time zone difference from Greenwich Mean Time (GMT), 
  • Content of the request (specific page), 
  • Access status/HTTP status code, 
  • Amount of data transferred, 
  • the page from which the request originated, 
  • Browser, 
  • operating system and its interface, 
  • language and version of the browser software. 

The legal basis for this is Article 6(1)(f) of the GDPR, whereby our legitimate interest arises from this purpose.

Web Hosting

We use an external web host to make our website accessible. To this end, the web host processes all data already mentioned in the previous section (Display of the Website). The legal basis for this is Article 6(1)(f) of the GDPR, whereby our legitimate interest arises from this purpose.

Cookie Consent

We give you the opportunity to consent to the use of cookies and use a cookie consent tool for this purpose. In doing so, we process all data already mentioned in the previous section (Display of the Website), as well as the information regarding whether, to what extent, and when you have given your consent. The purpose of this processing is to fulfill a legal obligation (Article 7(1) of the GDPR). The legal basis is Article 6(1), first sentence, point (c) of the GDPR.

Form

Our website features a form that allows you to communicate with us. All information you enter there is transmitted to us and processed by us.

Either:

  • the processing serves to initiate, execute, and/or terminate contracts (Purpose 1), or 
  • it allows you to contact us for another reason, e.g., to assert your right to information (Purpose 2). 

The legal basis for Purpose 1 is Article 6(1)(b) of the GDPR, and for Purpose 2, Article 6(1)(f) of the GDPR, whereby the legitimate interest arises from your request.

Recruiting

You have the option to apply for a position with us via the recruitment section of our website or through other contact channels. We collect this data to determine whether we can initiate a recruitment process or not. The legal basis is Article 6(1)(b) of the GDPR. In all other respects, our privacy policy for employees applies.

Analysis of User Behavior

We use cookies to analyze how you arrive at our website and what exactly you do there. Cookies are text files stored on your computer that enable us to perform this analysis (reports on your activities and interactions on the website, e.g., sequence of interactions, duration of visit).

We use this data and these analyses to improve our website and the user experience and to tailor them specifically to you and other data subjects. Further details can be found in the information about the tools (see below). 

The purpose of the processing is to optimize our website. The legal basis is Article 6(1)(a) of the GDPR.

Social Media/Networks

We are active on social media and networks. If you access our company pages on social media/networks from our website, certain data about you will be processed. This naturally also applies if you access these pages not via our website but through other means.

We would like to make it clear from the outset that we have no influence over which data is processed, how it is processed, or how long it is stored. There is always the possibility that the providers of these platforms will store your data and use it for advertising purposes, market research, and/or to tailor their services to your needs. Further details can be found below in the information about the providers.

The following data is processed in this context: 

  • cookie- or pixel-based data regarding your interactions with our company websites,
  • your email address,
  • your name,
  • your contact information

The processing serves to present our company. The legal basis is Article 6(1)(a) of the GDPR.

Video playback

Videos are displayed on our website via plugins from video and streaming portals. Each time a subpage or page containing a video clip is accessed, a direct connection is established to a server of the video portal. Further details can be found in the information provided by the respective providers.

The following data is processed in this context:

  • cookie-based data regarding your interactions with the video subpages,
  • Information about which video you clicked on

The purpose of this processing is to display videos and optimize our website. The legal basis is Article 6(1)(a) of the GDPR.

External fonts

We display text on our website using external fonts. In doing so, data is transmitted to the providers of these fonts to analyze and optimize the frequency of use and the performance of certain fonts. As soon as you visit our website, your browser sends HTTP requests to the provider’s server, transmitting, among other things, the URL of the requested font. This data is logged to determine usage frequency and generate statistical reports. In addition, cookie-based data regarding your interactions (e.g., sequence of interactions, duration of visit) is processed.

The purpose of this processing is to generate aggregated usage statistics regarding the popularity of fonts. The legal basis is Article 6(1)(a) of the GDPR.

Public Participation

Under certain conditions, you can participate in one of our projects via a registration form on our website. To do so, you will be redirected to the provider AUDITcapital GmbH, to whose privacy policy we refer. In this context, we receive all data necessary to execute your investment (contact details, information from investment agreements, billing data). The legal basis is Article 6(1)(b) of the GDPR.

Data Processing When Exercising Rights

If you exercise your rights under the GDPR or other legal provisions, we process your data to review these claims and, if necessary, fulfill them. The purpose of this processing is to comply with a legal obligation. The legal basis for this is Article 6(1)(c) of the GDPR in conjunction with the respective legal provision from which your right or claim arises.

Data Retention/Storage Period

We retain your data both during and after the end of the contract. Here we inform you how long the data is stored:

  • If you exercise your rights under the GDPR, communication data (correspondence via email, mail, etc.) is generated. We retain this data for three years. This period begins on December 31 of the calendar year in which we responded to your request. In doing so, we are pursuing our own legitimate interests. This is because, in the event of a dispute, we want to be able to prove that we have handled your claims correctly. The legal basis is Article 6(1)(f) of the GDPR. The three-year period is based on the statute of limitations for claims for damages (Sections 195, 199(1) of the German Civil Code (BGB)) and, additionally, the statute of limitations provisions under administrative offense law (Section 31(2)(1) of the German Administrative Offenses Act (OWiG) in conjunction with Article 83 of the GDPR).
  • If you assert other, non-GDPR rights, communication data is also generated, which we retain for three years. This period begins on December 31 of the calendar year in which we responded to your request. In doing so, we are pursuing our own legitimate interests. This is because we want to be able to prove, in the event of a dispute, that we have handled your claims correctly. The legal basis is Article 6(1)(f) of the GDPR. The three-year period is based on the statute of limitations for claims for damages (Sections 195, 199(1) of the German Civil Code (BGB)).
  • If you consent to data processing,
    we store the information that you have consented for three years. This period begins as soon as you withdraw your consent or the associated purpose ceases to exist, whichever occurs first. In doing so, we are pursuing our own legitimate interests. This is because we want to be able to prove in the event of a dispute that we have handled your claims correctly. The legal basis is Article 6(1)(f) of the GDPR. The three-year period is governed by the statute of limitations provisions for claims for damages (Sections 195, 199(1) of the German Civil Code (BGB)) and, additionally, the statute of limitations provisions under administrative offense law (Section 31(2)(1) of the German Administrative Offenses Act (OWiG) in conjunction with Article 83 of the GDPR).
    - We store the data we process based on your consent until you revoke your consent. The purpose is derived from the respective declaration of consent, and the legal basis for this is Article 6(1)(a) of the GDPR.

Deletion of Data

As soon as the aforementioned retention periods end, we delete your data. In doing so, we fulfill a legal obligation (Article 5(1)(a), (e) GDPR). The legal basis is Article 6(1), first sentence, (c) GDPR.

Recipients

Recipients within the European Union: Within the European Union, your data is processed by companies (recipients) in the following categories:

  • Hosting providers
  • Providers of cookie consent tools
  • Social networks
  • Software hosting companies,
  • providers of video conferencing systems,
  • law, tax, and auditing firms 
  • project management tools,
  • providers of whistleblower platforms,
  • Providers of accounting solutions
  • Providers of Microsoft assistant tools
  • Providers of translation tools

Recipients outside the European Union: Outside the European Union, your data is processed by the following specific companies (recipients):

  • Google: Various applications from Google Ireland Ltd. (Ireland – EU) are used, which has been appointed as a processor under Article 28 of the GDPR. A transfer of data to a third country (in this case, to Google LLC in the U.S.) cannot be ruled out but is justified under Article 45 of the GDPR. The following Google tools are used:
    - We use Google Analytics. Google generally processes IP addresses only within the European Union or the signatory states of the Agreement on the European Economic Area. Only in exceptional cases is the full IP address transmitted to a server of the provider in the USA and truncated there. To the best of our knowledge, the transmitted IP address is not merged with other data. We also use Google Analytics for cross-device analysis of visitor flows, which is carried out via
    a user ID.- We use Google Remarketing and Google Ads. Here’s how it works: When you interact with us online, for example by visiting our website, you can be identified as a suitable recipient of advertisements (so-called “ads”) through the use of cookies (so-called ad server cookies). With the help of these cookies, we can also measure and evaluate the success of an advertising campaign. If you subsequently visit Google pages (YouTube, Google search engine, etc.), you will be recognized based on these cookies, and our “ads” will be displayed to you (so-called “remarketing”). This occurs when your browser automatically establishes a direct connection to Google’s server. The “ads” are then delivered via so-called Google ad servers. The ad server cookies used in this process are generally valid for 30 days and are not used for personal identification. Typically, the following analytics data is stored: a unique cookie ID, the number of ad impressions per placement (frequency), the last impression (relevant for post-view conversions), and opt-out information (indicating that you do not wish to receive further ads).
    - You can restrict or prevent tracking, for example (a) by adjusting the settings in your browser software (in particular, blocking third-party cookies prevents you from receiving advertisements) or (b) by disabling cookies for conversion tracking by configuring your browser to block cookies from the provider’s domain. However, this setting will be deleted if you clear the cookies in your browser.
    - The purpose of this processing is to present our company, analyze user behavior regarding interaction with our website, and communicate with you via social media, including for advertising purposes
    where applicable.- We use Google Tag Manager. Here’s how it works: The tool allows us to integrate various codes and services into our website in a structured and simplified manner. In doing so, the tool implements so-called tags or triggers the integrated tags. When a tag is triggered, Google may also process personal data under certain
    circumstances.- We use DoubleClick. Here’s how it works: DoubleClick uses cookies to show you relevant ads, improve campaign performance reports, or prevent you from seeing the same ads multiple times. Using a cookie ID, Google tracks which ads were displayed in which browser to avoid duplicate ads. In addition, the use of cookie IDs enables the tracking of so-called conversions related to ad requests. This is the case, for example, if you see a DoubleClick ad and later visit our company’s website using the same browser and make a purchase there. Through the marketing tools used, your browser automatically establishes a direct connection to Google’s server. Through the integration of DoubleClick, Google receives the information that you have accessed the relevant part of our website or clicked on one of our ads. If you are registered with a Google service, Google can associate the visit with your respective account. Even if you are not registered or logged in, there is a possibility that Google will record and store your IP address
    . - My Fonts Counter: We use the analytics tool “My Fonts Counter” from My Fonts Inc. (USA), which has been commissioned in accordance with Article 28 of the GDPR. A transfer of data to a third country (in this case to Google LLC in the USA), which cannot be ruled out, is justified in accordance with Article
    45 of the GDPR. - Google Maps: We use Google Maps. Please note the following: Google Maps is a map display tool. The specific data transmitted depends, among other things, on whether the data subjects are using this website as logged-in users of a Google account or not.
  • Vimeo: The video playback tool “Vimeo” from Vimeo, LLC (USA) is used, which has been commissioned in accordance with Article 28 of the GDPR. A transfer of data to a third country (in this case, the USA), which cannot be ruled out, is justified for employee data in accordance with Article 46 of the GDPR and for all other data in accordance with Article 45 of the GDPR. The controller uses this video portal as follows: operation of its own channel, publication of media recordings. The terms used here are explained in the glossary at the end of this statement.
  • X (formerly Twitter): The social network “X” operated by Twitter International Company (Ireland – EU) is used. Further details on the manner of processing by this provider are described here: twitter.com/de/privacy. A transfer of data to a third country (in this case, the U.S.) that cannot be ruled out is justified under Article 46 of the GDPR. The controller uses this social network as follows: operation of a company page. The terms used here are explained in the glossary at the end of this statement.
  • LinkedIn: The social network “LinkedIn” operated by LinkedIn Ireland Unlimited Company (Ireland – EU) is used. A transfer of data to a third country (in this case, the USA), which cannot be ruled out, is justified in accordance with Article 46 of the GDPR. The controller uses this social network as follows: operation of a company page. The terms used here are explained in the glossary at the end of this statement.
  • Cloudflare: The content delivery network (CDN) “Cloudflare” operated by Cloudflare, Inc. (USA) is used; Cloudflare, Inc. has been appointed as a processor in accordance with Article 28 of the GDPR. A transfer of data to a third country (in this case, the USA) that cannot be ruled out is justified in accordance with Article 45 of the GDPR.
  • Monday Form: The form tool “Monday.com” from Monday.com Ltd. (Israel) is used. A transfer of data to a third country (in this case, Israel), which cannot be ruled out, is justified in accordance with Article 45 of the GDPR.

Entering the Premises

When you visit the above-mentioned property, we collect the following data upon your entry: name, reason for visit, date, time of entry and exit, and any voluntary additional information. The processing of this data serves both to protect you (for example, to determine whether you are still in the building in the event of a fire) and to protect our right of access, property, and possession, as well as for access control. The legal basis for this is Article 6(1)(f) of the GDPR, whereby our legitimate interest arises from the purposes mentioned.

Data Processing When Exercising Rights

If you exercise your rights under the GDPR or other legal provisions, we process your data to review these claims and, if applicable, fulfill them. The purpose of this processing is to comply with a legal obligation. The legal basis for this is Article 6(1)(c) of the GDPR in conjunction with the respective statutory provision from which your right or claim arises.

Data Retention/Storage Period

We retain your data both during and after the end of the contract. Here we inform you how long the data is stored:

  • If you exercise your rights under the GDPR, communication data (correspondence via email, mail, etc.) is generated. We retain this data for three years. This period begins on December 31 of the calendar year in which we responded to your request. In doing so, we are safeguarding our own legitimate interests. This is because, in the event of a dispute, we want to be able to prove that we have handled your claims correctly. The legal basis is Article 6(1)(f) of the GDPR. The three-year period is based on the statute of limitations for claims for damages (Sections 195, 199(1) of the German Civil Code (BGB)) and, additionally, the statute of limitations provisions under administrative offense law (Section 31(2)(1) of the German Administrative Offenses Act (OWiG) in conjunction with Article 83 of the GDPR).
  • If you assert other, non-GDPR rights, communication data is also generated, which we retain for three years. This period begins on December 31 of the calendar year in which we responded to your request. In doing so, we are pursuing our own legitimate interests. This is because we want to be able to prove, in the event of a dispute, that we have handled your claims correctly. The legal basis is Article 6(1)(f) of the GDPR. The three-year period is based on the statute of limitations for claims for damages (Sections 195, 199(1) of the German Civil Code (BGB)).
  • If you consent to data processing,
    we store the information that you have consented for three years. This period begins as soon as you withdraw your consent or the associated purpose ceases to exist, whichever occurs first. In doing so, we are pursuing our own legitimate interests. This is because we want to be able to prove in the event of a dispute that we have handled your claims correctly. The legal basis is Article 6(1)(f) of the GDPR. The three-year period is governed by the statute of limitations provisions for claims for damages (Sections 195, 199(1) of the German Civil Code (BGB)) and, in addition, the statute of limitations provisions under administrative offense law (Section 31(2)(1) of the German Administrative Offenses Act (OWiG) in conjunction with Article 83 of the GDPR).
    - We store the data we process based on your consent until you revoke your consent. The purpose is derived from the respective declaration of consent, and the legal basis for this is Article 6(1)(a) of the GDPR.

Deletion of Data

As soon as the aforementioned retention periods end, we delete your data. In doing so, we fulfill a legal obligation (Article 5(1)(a), (e) GDPR). The legal basis is Article 6(1), first sentence, (c) GDPR.

Recipients

Recipients within the European Union: Within the European Union, your data is processed by companies (recipients) in the following categories:

  • Providers of room management systems

Initial Contact During the Application Process

During the application process, we receive and review your application materials. This involves all data that you provide about yourself. If we remain interested, this is followed by a job interview, during which data (contact information, typically name, phone number, email address) is collected, stored, and used to schedule the appointment. If we remain interested, we will make you an offer of employment, in which case your contact information (typically name, phone number, email address) and the data from the employment contract (typically job description, vacation time, salary) will be processed. At any stage of the aforementioned processing steps, a rejection may also occur. The purpose of the aforementioned processing operations is to conduct the application process. The legal basis is Article 6(1)(b) of the GDPR.

Active Recruiting

Prior to the application process, we research data about potential employees from publicly available sources. We will contact you. In doing so, we process the data necessary to establish contact (e.g., name, address, email address) as well as job-specific data regarding your qualifications (e.g., degrees, certificates, etc.). The purpose of the aforementioned processing operations is to initiate the application process. The legal basis is Article 6(1)(b) of the GDPR.

Request for Certificates and Documentation

We request specific certificates and qualifications that are essential for the performance of the job. In doing so, we process the data contained in the certificates and other relevant documents. The purpose of the aforementioned processing operations is to initiate the application process and, subsequently, to carry out the employment relationship. The legal basis is Article 6(1)(b) of the GDPR.

Conducting a trial workday

You will participate in a trial workday, and we will record our observations, which we will subsequently use to make a decision regarding your application. In doing so, we process the data necessary for contacting you (e.g., name, address, email address) as well as any notes taken during the trial workday. The purpose of the aforementioned processing operations is to initiate the application process. The legal basis is Article 6(1)(b) of the GDPR.

Video Conferences

(1) We enable you to communicate via video conference. (2) If you opt for the video conference, we will obtain the necessary consent. For this purpose, we process the name, time, and status of the consent. The purpose is to fulfill a legal obligation. The legal basis is Article 6(1), first sentence, (c) of the GDPR in conjunction with Article 7(1) of the GDPR. (3) We conduct meetings via video conference. In doing so, we process the resulting image and audio data as well as any transcripts. The purpose is contract-related communication with you. The legal basis is Article 6(1), first sentence, lit. a of the GDPR. This is not precluded by the prohibition under Article 9(1) of the GDPR, as the exception under Article 9(2)(a) of the GDPR applies here.

Involvement of a Tax Advisory Firm

We transmit tax-related data concerning you (e.g., quotes, order confirmations, contracts, invoices, bank statements, etc.) to an external tax consulting firm. In doing so, we process your name as well as all data derived from invoices and payment receipts. We therefore seek support with accounting and other tax-related matters. The legal basis for this is Article 6(1), first sentence, point (f) of the GDPR, whereby our legitimate interest arises from the stated purpose. To the extent that the external tax consulting firm processes this data, this does not constitute commissioned processing (see DSK Brief 13), but rather a data transfer justified by Article 6(1)(f) of the GDPR.

Execution of the Employment Relationship

During the active employment relationship, all access and/or communication data related to the fulfillment of the employment contract (e.g., emails) is processed. The purpose of the aforementioned processing operations is the performance of the employment relationship. The legal basis is Article 6(1), first sentence, point (b) of the GDPR.

Collection of driver’s license data

Only if we provide you with a company car to fulfill your obligations under your employment contract will we collect your driver’s license data in advance through an external provider where you can have your driver’s license digitally recorded. In this process, all driver’s license data is processed. The purpose is to fulfill our traffic safety obligations and our obligations to insurers, namely to ensure that you are authorized to drive a company car. The legal basis is Article 6(1)(f) of the GDPR, whereby the legitimate interest arises from the aforementioned purposes.

Employee Benefits (with legitimate interest)

(1) In certain selected cases, we offer you the opportunity to take advantage of so-called employee benefits. (2) We transmit the contact data required for granting the benefits to external third-party providers (typically name, address, and information that you are employed by us). The purpose is to grant benefits; this is done to retain employees and increase the company’s attractiveness as an employer. The legal basis is Article 6(1)(f) of the GDPR, whereby the legitimate interest arises from the aforementioned purpose. Whether and, if so, which benefits are granted is the subject of an employment agreement that may still need to be concluded separately from this privacy notice. The mere mention of this possibility does not create a claim for you.

Issuance of Keys (including Logging)

In some cases, you will receive keys and/or access cards for entry to company premises, and the issuance of these items will be logged. In doing so, we process the following data: name, status of the issuance of the aforementioned items. The purpose of the aforementioned processing operations is to fulfill a data protection obligation, namely that of implementing adequate organizational security measures. The legal basis is Article 6(1)(c) of the GDPR in conjunction with Article 32 of the GDPR.

Issuance of access credentials (including logging)

In some cases, you will receive access credentials for company software and hardware, whereby both these access credentials and their assignment to you are recorded and stored. The assignment itself is also logged. In doing so, we process the following data: name, access credentials, status of the assignment of access credentials. The purpose of the aforementioned processing operations is to fulfill a data protection obligation, namely that of implementing adequate organizational security measures. The legal basis is Article 6(1)(c) of the GDPR in conjunction with Article 32 of the GDPR.

Issuance of Company Equipment (including Logging)

In some cases, you will receive company hardware, and the issuance of this hardware is logged. In doing so, we process the following data: name, status of hardware issuance. The purpose of the aforementioned processing operations is the internal organization of the services owed under the employment contract. The legal basis is Article 6(1)(f) of the GDPR, whereby the legitimate interest arises from the aforementioned purpose.

Mental Health Coaching

(1) In certain selected cases, we offer you the opportunity to participate in mental health coaching. (2) If you decide to do so, we will obtain the necessary consent. For this purpose, we process your name, the date and time, and the status of your consent. The purpose is to fulfill a legal obligation. The legal basis is Article 6(1)(c) of the GDPR in conjunction with Article 7(1) of the GDPR. (3) We do not process any data regarding participation in the coaching and/or its content ourselves, but only receive an invoice. The legal basis is Article 6(1)(a) of the GDPR.

Changes to Data Processing

If we change the processing, in particular by engaging new recipients, we will inform you of the change via email by sending you the updated privacy policy. The purpose is to fulfill the transparency obligations under the GDPR (Articles 12–14 GDPR). The legal basis is Article 6(1)(c) of the GDPR.

Exercising Rights

If you exercise your rights under the GDPR or other legal provisions, we process the data to review these claims and, if necessary, fulfill them. The purpose is to comply with a legal obligation. The legal basis is Article 6(1), first sentence, lit. c of the GDPR in conjunction with the provision from which the legal obligation arises.

Conflicts in the employment relationship

In the event of a conflict under labor law between you and us, the data will be processed to issue relevant statements and, if necessary, to seek external legal counsel. The following data will be processed in this context: name, contact information, and all proceedings related to the labor law conflict. The processing serves the purpose of obtaining external labor law advice/support as well as exercising our own rights. The legal basis is Article 6(1), first sentence, point (f) of the GDPR, whereby the legitimate interest arises from the aforementioned purposes. To the extent that data is processed externally, this does not constitute commissioned processing (see DSK Brief 13), but rather a data transfer, which in turn is justified by Article 6(1)(f) of the GDPR. This therefore constitutes a case of other outsourcing.

Receipt and Processing of Whistleblower Reports

We offer you the opportunity to contact us as a so-called whistleblower. Incoming whistleblower reports from employees are acknowledged and processed. Personal data is processed only to the extent that the report is not submitted anonymously. This includes the following: name(s), content of the report. The purpose of the processing is to fulfill a legal obligation under Sections 12 et seq. of the Whistleblower Protection Act (HinSchG). The legal basis is Article 6(1)(c) of the GDPR.

Production of Media Recordings

(1) In certain selected cases, we allow you to have media recordings (photos, video, audio) made. (2) If you decide to do so, we will obtain the necessary consent. For this purpose, we process the name, time, and status of the consent. The purpose is to fulfill a legal obligation. The legal basis is Article 6(1)(c) of the GDPR in conjunction with Article 7(1) of the GDPR. (3) Media recordings will be made of you and, to the extent consent permits, may also be published in certain cases to be determined by us. In doing so, we process image, video, and audio data. The purpose is to present our company to the public. The legal basis is Article 6(1), first sentence, letter a of the GDPR. This is not precluded by the prohibition under Article 9(1) of the GDPR, as the exception under Article 9(2)(a) of the GDPR applies here.

Fulfilment of Additional Legal Obligations

In the employment relationship, data is processed to fulfill additional legal obligations not yet mentioned here. This includes the following scenarios:

  • Processing of all data regarding participation in training and instruction, including in particular first aid training (Section 14 SGB VII in conjunction with DGUV Regulation 1), Conducting data protection training for employees (Article 32 GDPR), training for EuP (Section 14 SGB VII in conjunction with DGUV Regulation 3), Driver safety training (Section 3 ArbSichV), fire extinguisher training (Section 14 SGB VII in conjunction with DGUV Regulation 1), IT training (BSI Critical Infrastructure Regulation, Article 32 GDPR). The following data is processed in this context: name, company contact information, communication data, status, and, if applicable, the date and time of participation.
  • Processing of all data when ordering hardware or software that must be provided for occupational safety reasons, e.g., computer glasses (Section 3 ArbSchG). The following data is processed in this context: name, company contact information, communication data, proof of the necessity of the hardware or software, time of order, time of delivery, time of commissioning, costs.
  • Processing of all data in connection with maintaining a first-aid logbook, in particular the retention of completed first-aid logbook pages (Section 14 of Book VII of the Social Code (SGB VII) in conjunction with DGUV Regulation 1, Section 24(6)). The following data is processed in this context: name, company contact information, communication data, data regarding all first-aid incidents, in particular the type of incident, time, measures taken, and the identity of the assisting and affected employees/persons.
  • Processing of all data generated in the course of occupational medical examinations (Section 3 ArbSchG). The following data is processed in this context: name, company contact information, communication data, time of the appointment, and status regarding attendance at the appointment.
  • Processing of all data generated in connection with occupational eye examinations (Section 3 ArbSchG). The following data is processed: name, work contact information, communication data, appointment time, and status regarding attendance at the appointment.
  • Other training courses for which training obligations currently exist or will exist in the future. The following data is processed in this context: name, company contact information, communication data.

All processing steps serve to fulfill the legal obligations specified in the respective parenthetical notes. The legal basis is Article 6(1)(c) of the GDPR in conjunction with the standards specified in the respective parenthetical note.

Fulfillment of other obligations under the employment contract

In the employment relationship, data is processed for the purpose of carrying out the employment relationship. This includes, in particular but not exclusively, the following scenarios:

  • The filing of planning documents and documentation with substation suppliers is recorded, stored, and further utilized. The following data is processed in this context: name, company contact information, communication data, status and time of entry, and the identity of the employee making the entry.
  • The documentation of the filing of planning documents as well as the documentation with substation installers is recorded, stored, and further utilized. The following data is processed in this context: name, company contact information, communication data, status and time of entry, identity of the employee making the entry.
  • Absences due to parental leave, illness, vacation, special leave, educational leave, and unpaid leave are recorded, stored, and further used. The following data is processed in this context: name, company contact information, communication data, time period, reason, and evidence of the reason for the absence.
  • In the case of procurements/purchases, including the ordering of work clothing that concerns you, the following data is collected, stored, and used: name, company contact information, communication data, clothing size, assignment of work clothing, condition of the work clothing.
  • Internal communication takes place regarding the management of work clothing. The following data is processed in this context: name, work contact information, communication data, clothing size, assignment of work clothing, condition of work clothing.
  • In certain cases, electronic signatures are obtained. The following data is processed in this context: name, work contact information, communication data, signature image, time of signature, content of the signed document.
  • Hotel reservations are made and documented for you. The following data is processed in this context: name, company contact information, communication data, status of the business trip, duration of the business trip, costs of the business trip.
  • The reimbursement of other travel expenses for business trips is recorded, stored, and used. The following data is processed in this context: name, company contact information, communication data, status of the business trip, duration of the business trip, costs of the business trip.

All processing steps serve the purpose of internal communication as well as the fulfillment of obligations under the employment contract. The legal basis is Article 6(1)(b) of the GDPR.

Video recordings on the premises of the solar parks

Our solar parks are under video surveillance, and the video surveillance data (image data, recording period, recording location) is processed to protect our right of access, our property, and our possessions, as well as to fulfill legal obligations (Article 32 GDPR: access control, Section 8a of the BSI Act: special security measures). Furthermore, still images are recorded several times a day to measure and statistically evaluate any environmental impacts (e.g., hail, snowfall). To the extent that the processing serves to protect our property rights, our property, and our possessions, the legal basis is Article 6(1)(f) of the GDPR, whereby the legitimate interest arises from the aforementioned purposes. To the extent that the processing serves to fulfill legal obligations, Article 6(1)(c) of the GDPR is the legal basis. To the extent that the processing serves the measurement and evaluation of any environmental impacts, Article 6(1)(f) of the GDPR is the legal basis, whereby the legitimate interest arises from the aforementioned purpose.

Data logging when using WebGIS and/or QGIS

If you use the tools mentioned in the heading as part of your contractual relationship with us, we collect the following data: 

  • for WebGIS (username, number_of_logins, last_login) 
  • for QGIS (ld, plugin, created_by - username, created_at, last_update)

The processing serves only for internal monitoring (usage statistics, troubleshooting). The legal basis is Article 6(1)(f) of the GDPR, whereby the legitimate interest arises from the aforementioned purpose.

Travel Expense Reports

During active employment, travel and booking data are processed for business trips in order, on the one hand, to facilitate the business trip (Purpose 1) and, on the other hand, to correctly record the associated expenses for tax purposes (Purpose 2). In this context, all data related to the booking and settlement of the business trip (start, end, business reason, name of the traveler, identification data from the personnel file, booking-related invoices, and payment receipts) is processed. The legal basis for Purpose 1 is Article 6(1)(b) of the GDPR, and for Purpose 2, Article 6(1)(c) of the GDPR in conjunction with Section 147 of the German Fiscal Code (AO).

Data Retention/Storage Period

We retain your data both during and after the end of the contract. Here we inform you how long the data is stored:

  • Internal records (e.g., annual financial statements, accounting documents) must be retained for 10 years, beginning on December 31 of the calendar year in which the respective document was created. The processing serves to fulfill a legal obligation and is based on Article 6(1)(c) of the GDPR in conjunction with Section 147 of the German Fiscal Code (AO) and Section 257 of the German Commercial Code (HGB).
  • Business communication data (e.g., customer letters) and other tax-related documents must be retained for 6 years, beginning on December 31 of the calendar year in which the respective document was created. The processing serves to fulfill a legal obligation and is based on Article 6(1)(c) of the GDPR in conjunction with Section 147 of the German Fiscal Code (AO) and Section 257 of the German Commercial Code (HGB).
  • Data from working time records must be retained for 2 years, starting on December 31 of the calendar year in which the respective document was created. The processing serves to fulfill a legal obligation and is based on Article 6(1)(c) of the GDPR in conjunction with Section 16 of the Working Hours Act (ArbZG) and Section 17 of the Minimum Wage Act (MiLoG).
  • Data from the payroll account must be retained for 6 years, beginning on December 31 of the calendar year in which the last recorded payroll payment was made. The processing serves to fulfill a legal obligation and is based on Article 6(1)(c) of the GDPR in conjunction with Section 41 of the Income Tax Act (EStG).
  • Data regarding health insurance status and sick leave are retained for 5 years. The processing serves to fulfill a legal obligation and is based on Article 6(1)(c) of the GDPR in conjunction with Section 198 of the German Social Code, Book V (SGB V) and Section 165 of the German Social Code, Book VII (SGB VII).
  • Data generated when you assert data protection claims is retained for three years, beginning on December 31 of the calendar year in which we responded to your claim. The processing serves to safeguard the interest in defending against claims and is based on Article 6(1)(f) of the GDPR, whereby the legitimate interest arises from the aforementioned purpose. The duration of the legitimate interest is determined by the statute of limitations provisions for claims for damages (Sections 195, 199(1) of the German Civil Code (BGB)) and, additionally, from the statute of limitations provisions of administrative offense law (Section 31(2)(1) of the German Administrative Offenses Act (OWiG) in conjunction with Article 83 of the GDPR).
  • Data generated when you assert other claims is retained for three years, beginning on December 31 of the calendar year in which we responded to such claims. The processing serves to safeguard the interest in defending against claims and is based on Article 6(1)(f) of the GDPR, whereby the legitimate interest arises from the aforementioned purpose. The duration of the legitimate interest is determined by the statute of limitations for claims for damages (Sections 195, 199(1) of the German Civil Code (BGB)).
  • Data based on consent must be retained until the consent is revoked or until the purpose associated with the processing ceases to exist, whichever occurs first. Retention serves the purpose associated with the consent and is based on Article 6(1)(a) of the GDPR. 
  • Data proving the granting of consent must be retained for 3 years, beginning with the date of withdrawal of consent or the cessation of the purpose, whichever occurs first. The processing serves to safeguard the interest in defending against claims and is based on Article 6(1), first sentence, (f) of the GDPR, whereby the legitimate interest follows from the aforementioned purpose. The duration of the legitimate interest is determined by the statute of limitations provisions of the Administrative Offenses Act (Section 31(2)(1) OWiG in conjunction with Article 83 of the GDPR). 
  • Data from a job application is retained for 6 months, beginning with the date of receipt of the rejection notice. The processing serves to safeguard the interest in defending against claims under the AGG and is based on Article 6(1), first sentence, lit. f GDPR, whereby the legitimate interest follows from the aforementioned purpose. The duration of the legitimate interest is determined by the time limits set forth in Section 15(4) of the Unfair Competition Act (UWG), plus the period after which the receipt of a complaint can no longer be expected.
  • Video recordings on the solar park premises are generally retained for only 48 hours. The legal basis is Article 6(1)(f) of the GDPR, whereby the legitimate interest arises from the aforementioned purposes (protection of our right of access, our property, and our possessions). If these purposes are compromised (e.g., trespassing, theft, property damage), we retain the data for as long as necessary to pursue our rights (e.g., claims for damages), but delete it no later than upon final clarification of the facts. 
  • Still images derived from the video recordings and created for the measurement and evaluation of any environmental impacts are retained for a maximum of 5 years, with the period beginning on December 31 of the calendar year in which the recordings were made. The legal basis is Article 6(1)(f) of the GDPR, whereby the legitimate interest arises from the aforementioned purpose.
  • Monitoring data generated during the use of WebGIS (username, number_of_logins, last_login) and/or QGIS (ld, plugin, created_by - username, created_at, last_update) is deleted 12 months after the data is collected. The legal basis for retention is Article 6(1)(f) of the GDPR, whereby the legitimate interest arises from the fact that access to the data may be necessary within one year to resolve current issues.

Deletion of Data

After the retention periods have expired, the data is deleted. The deletion serves to fulfill a legal obligation and is based on Article 6(1), first sentence, lit. c GDPR in conjunction with Article 5(1), lit. a, e GDPR.

Recipients

The following recipients and other external parties process your data:

Recipients within the European Union: Within the European Union, your data is processed by companies (recipients) in the following categories:

  • Backup tool providers
  • Software hosting companies,
  • Providers of video conferencing systems and remote work tools,
  • Law firms, tax firms, and auditing firms,
  • Providers of password management systems,
  • project management tools,
  • providers of whistleblower platforms,
  • providers of compliance and training solutions,
  • Providers of (payroll) accounting solutions,
  • providers of Microsoft productivity tools,
  • Providers of translation tools,
  • Providers of work equipment (e.g., work clothing),
  • Providers of HR systems,
  • Providers of employee benefits,
  • Providers of security and surveillance services.
  • Social media providers (for recruiting purposes)
  • Providers of travel expense reporting tools

Recipients outside the European Union: Outside the European Union, your data is processed by the following specific companies (recipients):

  • Microsoft: Various applications from Microsoft Corporation (USA) are used, which has been commissioned in accordance with Article 28 of the GDPR, namely: Microsoft 365 Cloud, Microsoft Teams (project management tool), Microsoft Teams (video conferencing tool), Microsoft Bookings, Microsoft Forms, SharePoint. A transfer of data to a third country (in this case, the USA), which cannot be ruled out, is justified in accordance with Article 45 of the GDPR.
  • New Relic: The website monitoring tool “New Relic” from New Relic, Inc. (USA) is used; New Relic, Inc. has been commissioned in accordance with Article 28 of the GDPR. A transfer of data to a third country (in this case, the USA), which cannot be ruled out, is justified in accordance with Article 45 of the GDPR.
  • Lacework: The IT security tool “Lacework” from Lacework, Inc. (USA) is used. A data transfer to a third country (in this case, the USA) that cannot be ruled out is justified in accordance with Article 46 of the GDPR.
  • ShareFile: The IT tool “ShareFile” from Citrix Systems Inc. (USA) is used, which has been commissioned in accordance with Article 28 of the GDPR. A data transfer to a third country (in this case, the USA) that cannot be ruled out is justified in accordance with Article 46 of the GDPR.
  • Monday.com: The collaboration tool “Monday.com” from Monday.com Ltd. (Israel) is used. A data transfer to a third country (in this case, Israel) that cannot be ruled out is justified in accordance with Article 45 of the GDPR.
  • Atlassian: The project management tool from Atlassian Pty Ltd (Australia) is used, which has been commissioned in accordance with Article 28 of the GDPR. A data transfer to a third country (in this case, Australia) that cannot be ruled out is justified in accordance with Article 46 of the GDPR.
  • Autodesk: The “Autodesk” project management tool from Autodesk, Inc. (USA) is used; Autodesk, Inc. has been appointed as a processor in accordance with Article 28 of the GDPR. A transfer of data to a third country (in this case, the USA), which cannot be ruled out, is justified under Article 46 of the GDPR for employee data and under Article 45 of the GDPR for all other data.
  • Adobe: In connection with the use and creation of documents, software solutions from Adobe Systems Software Ireland Limited (Ireland – EU) are used, which has been appointed as a processor in accordance with Article 28 of the GDPR.  A transfer of data to a third country (in this case, to Adobe Inc., USA) cannot be ruled out and is justified for employee data in accordance with Article 46 of the GDPR and for all other data in accordance with Article 45 of the GDPR.
  • LinkedIn (social network): The social network “LinkedIn” operated by LinkedIn Ireland Unlimited Company (Ireland – EU) is used. However, it cannot be ruled out that data may be transferred to or integrated with the parent company, LinkedIn Corporation (USA). A data transfer to a third country (in this case, the USA) that cannot be ruled out is justified under Article 46 of the GDPR. The following tools are used: LinkedIn (Company Page), LinkedIn (Recruiting)
  • Dropbox: The cloud service “Dropbox” provided by Dropbox, Inc. (USA) is used; Dropbox, Inc. has been appointed as a processor in accordance with Article 28 of the GDPR. A data transfer to a third country (in this case, the USA), which cannot be ruled out, is justified in accordance with Article 45 of the GDPR.