PRIVACY POLICY


General information

Controller and Data Protection Officer
Legal basis for the processing of your personal data
Rights of the data subject
Storage period for personal data

Contractual processing


Application data


Data processing in relation to the website

Logfiles, hosting
Contact
Cookies


Information for prospective customers


Data sharing: General and contractual purposes


Tools used in operating the website and online services


Our presence on social media

Instagram (Meta)



General information

The following policy provides you with information about the type of personal data that we collect as the data controller, the purpose of collection, and the extent to which the data is made accessible to third parties.

Controller and Data Protection Officer

EMMA gemeinnützige GmbH
Hornstrasse 13 
10963 Berlin, Germany 
T +49(0)30 548 499 86 
E post@emmaapfel.de
emmaapfel.de


Datenschutzbeauftragte
Frau Nele Trenner, Rechtsanwältin
E datenschutz@emmaapfel.de


Legal basis for the processing of your personal data


The processing of personal data requires a legal basis, which we would like to explain to you in our case below. For processing of personal data for which we obtain the consent of the data subject, Article 6(1) point (a) of the EU General Data Protection Regulation (GDPR) serves as the legal basis.

For processing of personal data necessary for the performance of a contract to which the data subject is a party, Article 6(1) point (b) GDPR serves as the legal basis. This also includes processing operations that are necessary for carrying out pre-contractual measures.

Where processing of personal data is necessary for compliance with a legal obligation that applies to our company, Article 6(1) point (c) GDPR serves as the legal basis.

If processing is necessary to pursue the legitimate interests of our company or of a third party and the interests or fundamental rights and freedoms of the data subject do not override those interests, Article 6(1) point (f) GDPR serves as the legal basis for the processing. Our company's legitimate interests consist in conducting our business activities and in analyzing, optimizing, and maintaining the security of our online services.


Rights of the data subject

You have the right to access information about the personal data that we have stored about you. In particular, you can request information about the purposes of processing, the categories of personal data, the categories of recipients to whom your data has been or will be disclosed, the planned storage period, the origin of your data if it was not collected from us, and the use of automated decision-making including profiling, with meaningful information about the specifics of this.

The legal provisions also give you the right to rectification of inaccurate data, restriction of processing, data portability, and erasure of your personal data. To exercise any of these rights, please send us an email with the subject "Data Protection". You also have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data violates the legal provisions.


For reasons arising from your particular situation, you may object at any time to the processing of personal data concerning you which is carried out on the basis of point (e) or (f) of Article 6(1) GDPR; the same applies to profiling based on those provisions (Article 21 GDPR). Provided the legal requirements are met, we will then stop processing your personal data. If we use direct marketing, you have the right to object at any time to the processing of personal data concerning you for the purpose of such marketing; this also applies to profiling insofar as it is related to such direct marketing.

Your objection means that your personal data will no longer be processed for these purposes. 


If you have given your consent, you have the right to withdraw that consent at any time. This does not affect the lawfulness of processing based on consent prior to its withdrawal. We do not currently carry out any automated decision-making, including profiling.


If you exercise one of the aforementioned rights as a data subject, we will process the personal data that we collect in this process to respond to your request. Your personal data is then being processed to fulfill a legal obligation.

In the event of an objection, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights, and freedoms or your personal data serves the purpose of establishing, exercising, or defending legal claims.


Storage period for personal data

Unless we provide specific storage information in individual sections below, the following applies: We store personal data for the duration of the respective statutory retention period or for as long as the purpose of its collection exists. After the retention period has expired, the data is routinely erased, unless it is required for initiating or fulfilling a contract. If user data is not erased because it is required for other legally permissible purposes, its processing is restricted as far as possible. The data is therefore blocked where possible and is not processed for other purposes. This applies, for example, to user data that must be retained for legal reasons under commercial or tax law.


Contractual processing

If you request or enter into a contractual relationship with us, we generally collect the following data: Title, first and last name, email address, postal address, telephone/cell phone number, information necessary for initiation and execution of the contract.


We need this data to identify you as a contractual partner, to execute the contract, to contact you, and for billing purposes. The data processing is carried out at your/our request or instruction and is necessary for the purposes specified for fulfillment of and compliance with the obligations arising from the contractual relationship on both sides.


We may also process data on the basis of a legitimate interest, for example when asserting or defending against claims arising from the contractual relationship. The personal data collected is stored until the end of the contractual relationship and then erased, unless we are required to store it for a longer period in accordance with legal retention and documentation obligations under tax and commercial law (e.g. the German Commercial Code (HGB), Criminal Code (StGB), or Fiscal Code (AO)).

We use the data of our (future) contractual partners and employees (first name, last name, and address if necessary) to carry out checks against so-called sanctions lists. Sanctions lists are centrally compiled and maintained lists of individuals, associations, or companies against whom government economic or legal restrictions have been imposed. Various regulations oblige us to take measures to ensure that we do not support business partners, suppliers, or (potential) employees if they appear on the lists. We only use the data to ensure that the individuals in question are not on any sanctions lists. We need this information to fulfill our legal obligations and to avoid possible sanctions ourselves. This is also in our legitimate interest.



Application data

When you apply to us, you provide us with your data. We process the data you submit to us in connection with your application to check your suitability for the position and to carry out the application process. Please note that your data is then accessible to our HR department and the departments relevant to the position to be filled. For data protection reasons, we ask that you only provide the data necessary for your application. The legal basis for the processing of your personal data in application procedures is Section 26 of the German Federal Data Protection Act (BDSG) and/or Art. 6(1) point (b) GDPR. These provisions permit processing of data necessary for a decision on establishing an employment relationship. Should the data be required for any legal proceedings after the application process has been completed, data processing may take place on the basis of the provisions of Art. 6(1) point (f) GDPR for the purpose of pursuing our legitimate interests. Our interest in this context lies in asserting or defending against legal claims.


In the event of a rejection, applicant data is erased no later than 6 months after the application is rejected. If you consent to longer retention of your personal data, we will add your data to our applicant pool. The data is then erased after two years. If you are offered a position in the course of the application process, your data is stored permanently for the purpose of carrying out the employment relationship. You can change or erase your application at any time and revoke any consent you may have given in connection with it at any time.


Data processing in relation to the website

Log-Dateien, hosting

Data that your browser transmits to us is stored automatically as part of the server statistics in the context of our legitimate interest in analysis and for security reasons (so-called "logfiles").


The following data is stored:

language and version of the browser software

operating system used and its interface

referrer URL (the page visited previously)

hostname of the accessing computer (IP address)

date and time of the server request

time zone difference from Greenwich Mean Time (GMT) 

content of the request (specific page)

volume of data transferred

access status/HTTP status codee


We are generally unable to attribute this data to specific individuals. The data is not combined with other data sources. The data is erased following statistical evaluation within 7 days. Data that has to be retained for evidentiary purposes is exempt from erasure until the related incident has been fully investigated.


We make use of hosting services. These are used to provide infrastructure and platform services, computing capacity, storage space and database services, security services, and technical maintenance services to maintain the operation of this website.

In this context, we or our hosting provider process inventory data, contact data, content data, contract data, usage data, meta and communication data of customers, prospective customers, and visitors to the website based on our legitimate interests in efficient and secure provision of this website.


Contact

When you contact us by email or via a contact form, your details are stored by us so that we can answer your questions. As a matter of principle, data is not shared with third parties unless applicable data protection regulations justify such a transfer or we are legally obliged to do so. You can revoke the consent you have given to processing at any time with effect for the future. In the event of revocation, your data is erased immediately, unless there is a legal exception regarding further processing. Otherwise your data is erased once we have processed your request or the purpose of storage no longer applies, provided that there are no other conflicting legal exceptions.


Cookies

Cookies are small text files that are stored on your device, by means of which the entity that sets the cookie can obtain certain information. They serve to make the website more user-friendly and effective and/or to make navigation easier for you. We only use cookies that are not strictly necessary if you have given your consent. You can revoke that consent at any time with regard to future use. 

Consent is voluntary and you can also use our website without accepting cookies. You can also configure your browser settings according to your preferences and, for example, reject acceptance either of third-party cookies or of all cookies, or erase the cookies that have already been stored. If you do not accept cookies, please note that our website may not function correctly. Unless specified otherwise in the individual sections of this privacy policy or on the cookie banner, the lifespan of the cookies is 24 months.

We currently do not use any cookies on our website that affect data protection or are not necessary for technical reasons.


Information for prospective customers

If you, as our contractual partner, have concluded a contract for our services, we provide you with further information about similar services that we offer using the email address given on conclusion of the contract (Section 7 III of the German Act against Unfair Competition (UWG)). You may object to receiving this information at any time. These mailings are carried out on the basis of our legitimate advertising interest.


Data sharing: General and contractual purposes

We share data with third parties if this is necessary for the fulfillment of the contract and/or if we are legally obligated and/or entitled to do so in individual cases. The data is typically passed on to commissioned service providers, including those providing services in the areas of hosting, operation, maintenance, and support for IT systems, communication systems, and disposal. Furthermore, your data may be transmitted to postal or delivery services, banks, tax advisors/auditors, and lawyers.


Tools used in operating the website and online services

We do not use any tools or external service providers for analysis, optimization, or business operation of our website. 

If your data is to be used for other purposes, we will inform you in advance and only use the data if you have expressly given your further consent beforehand.


Our presence on social media

You will find we have an online presence on various social networks and platforms. We use these profiles to communicate with our customers, prospective customers, and users who are active there and to inform them about our services and our company. 

The processing of personal data of active users of social media is based on our legitimate interests in communicating with and providing information to users. If users have given their consent to data processing within the framework of the respective social platform, the processing is carried out on this basis of that consent.


When you visit one of our social media profiles, we are jointly responsible with the operator of the social platform for the data processing operations triggered by that visit. You can generally assert your rights (to access, rectification, erasure, restriction of processing, data portability, and complaint, see the following section "Rights of the data subject") in respect of both us and the operator of the respective social platform.

We would like to point out that, despite our joint responsibility, we do not have full control over the data processing operations of the social platform, and we may forward the request to assert your rights as a data subject to the platform operator so that it can be dealt with more effectively. Our options are generally determined by the company policy of the respective operator.

Our information about data storage can be found below. We have no control over the storage period for data stored by the operator of the social platform for its own purposes. For details, please contact the operator of the social network directly (e.g. via their privacy policy, see below).


Depending on the specific social media platform, user data processing may also take place outside the European Union. We have taken appropriate measures to ensure compliance with European data protection law: EU standard contractual clauses have been agreed with US companies, or they are certified under the Data Privacy Framework (DPF).

User data is typically processed by the platforms for market research and advertising purposes. For example, user profiles can be created based on user behavior and the user interests derived from that. User profiles may then be used, for example, to place advertising on or outside the platforms that is assumed to correspond to the interests of the user. Cookies are usually stored on user's computer for this purpose and record their behavior and interests. User profiles can also store data regardless of the devices used by the users. This is particularly the case if users have their own account on the respective platform and are logged in.


For a detailed description of the processing activities and the options for objecting, please follow the links below.


Instagram (Meta)

(Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Irland)

Privacy policy/opt-out: https://privacycenter.instagram.com/policy/