1. General information on data protection
1.1. Introduction
MTB GmbH attaches great importance to data protection. Below, we provide information about the processing of personal data when using our website and during the application process. Personal data is any data that can be related to you personally, e.g., name, address, email addresses, user behavior.
1.2. Responsible party
The responsible party within the meaning of the General Data Protection Regulation is: MTB GmbH | Rauhe Wiese 18 | 31171 Nordstemmen | Phone: +49 5069 80615-0 | Fax: +49 5069 80615-19 | Email: info@mtb-bau.de
1.3. Data protection officer
The data protection officer of the controller is:
List + Lohr Datenschutz und Informationssicherheit GmbH
Garvensstraße 4, 30519 Hannover, Germany
Email: team@datenschutz-hannover.de
1.4. Your rights as a data subject and right to lodge a complaint
As a data subject, you have the following rights with regard to your personal data:
- Right to information pursuant to Art. 15 GDPR
- Right to rectification pursuant to Art. 16 GDPR
- Right to erasure pursuant to Art. 17 GDPR
- Right to restriction of processing pursuant to Art. 18 GDPR
- Right to notification pursuant to Art. 19 GDPR
- Right to data portability pursuant to Art. 20 GDPR
- Right to object to processing pursuant to Art. 21 GDPR In addition, pursuant to Art. 7 (3) GDPR, you have the right to withdraw your consent to the processing of personal data at any time. Please note that the withdrawal only applies to the future. Processing that took place before the withdrawal is not affected. Please also note that we may be required to retain certain data for a specific period of time in order to comply with legal requirements. Furthermore, you have the right to lodge a complaint with a data protection supervisory authority pursuant to Art. 77 GDPR if you believe that the processing of your personal data is not lawful. The right to lodge a complaint exists without prejudice to any other administrative or judicial remedy.
2. Specific information on data processing on the website
2.1. Provision of the website
The following information applies only to this website. It does not apply to other websites to which we merely refer via a hyperlink. We cannot accept any responsibility for the confidential handling of your personal data on these third-party websites.
2.2. Processing of personal data when visiting the website
When using the website for informational purposes only, i.e. when you otherwise transmit information to us, we only collect the personal data that your browser transmits to our server. If you wish to view our website, we collect the following data, which is technically necessary for us to display our website to you, to ensure stability and security, and to optimize the use of the website (the legal basis is Art. 6 (1) (f) GDPR):
- IP address of the user,
- Date and time of access to the website,
- Time zone difference to Greenwich Mean Time (GMT),
- Content of the request (specific page),
- Access status/HTTP status code,
- Amount of data transferred in each case,
- Websites accessed by the user’s system via our website,
- websites from which the user’s system accesses our website,
- information about the browser type and version used,
- the user’s operating system and its interface,
- the Internet service provider of the accessing system,
- language and version of the browser software,
- other similar data and information that serves to avert danger in the event of attacks on our IT systems. The data is also stored in our system’s log files. This data is not stored together with other personal data of the user. Legal basis for data processing: The legal basis for the temporary storage of data and log files is Art. 6 (1) lit. f GDPR.
Purpose of data processing:
The temporary storage of the IP address by the system is necessary to enable the website to be delivered to the user’s computer. For this purpose, the user’s IP address must remain stored for the duration of the session. These purposes constitute our legitimate interest in data processing pursuant to Art. 6 (1) lit. f GDPR.
Duration of storage:
The data is deleted as soon as it is no longer necessary for the purpose for which it was collected. In the case of data collection for the provision of the website, this is the case when the respective session has ended. In the case of data storage in log files, this is the case after 7 days at the latest. Storage beyond this period is possible. In this case, the IP addresses of the users are deleted or alienated so that it is no longer possible to assign the calling client.
Right to object and right to erasure:
The collection of data for the provision of the website and the storage of data in log files is essential for the operation of the website. There is therefore no possibility to object. Further storage may take place in individual cases if this is required by law.
External hosting:
Our website is hosted on the server of an external service provider (hosting company: United Internet; server location: Germany). The data mentioned in 2.2. is stored on the servers of the hosting provider. The hosting provider is used for the purpose of fulfilling our contractual obligations to our prospects and customers (Art. 6 (1) (b) GDPR). We have chosen a professional service provider to ensure the optimal provision of our online services (Art. 6 (1) (f) GDPR). Our service provider will only process your data in the form necessary to fulfill its contractual obligations or in accordance with our instructions. We have accordingly concluded a contract for order processing with our service provider.
SSL encryption:
Our website uses SSL encryption. This encryption is used, for example, for inquiries that you submit to us via our website. Please ensure that SSL encryption is activated on your side for such activities. The use of encryption is easy to recognize: the display in your browser address bar shows “https://”. Data encrypted via SSL cannot be read by third parties.
2.3. Use of OpenStreetMap
We use a map section from OpenStreetMap (www.openstreetmap.de) on our website. OpenStreetMap is an open-source mapping tool. In order for the map to be displayed, your IP address is forwarded to OpenStreetMap. You can see which data OpenStreetMap processes in the OpenStreetMap privacy policy. In this respect, OpenStreetMap is the data controller in accordance with Art. 4 No. 7 GDPR.
2.4. Contact
You can contact us by email, post, and telephone. The legal basis for the processing of data is Art. 6 para. 1 lit. a GDPR if the user has given their consent. If the purpose of the email contact is to conclude a contract, the legal basis for the processing is Art. 6 para. 1 lit. b GDPR. The legal basis for the processing of data transmitted in the course of sending an email is Art. 6 (1) lit. f GDPR. The processing of personal data from the email serves us solely for the purpose of processing the contact request. In the event of such contact, this also constitutes the necessary legitimate interest in the processing of the data. The data will be deleted as soon as it is no longer necessary for the purpose for which it was collected. For personal data sent by email, this is the case when the respective conversation with the user has ended. The conversation is ended when it can be inferred from the circumstances that the matter in question has been conclusively clarified. The user has the option of revoking their consent to the processing of personal data at any time. If the user contacts us by email, they can object to the storage of their personal data at any time. In such a case, the conversation cannot be continued. All personal data stored in the course of contacting us will be deleted in this case. We delete the data collected in this context once storage is no longer necessary, or restrict processing if there are legal retention obligations.
2.5. Data protection for applications and in the application process
We collect and process the personal data of applicants for the purpose of the application process. Processing may also be carried out electronically. This is particularly the case if an applicant sends us the relevant application documents electronically. If we conclude an employment contract with an applicant, the data transmitted will be stored for the purpose of processing the employment relationship in compliance with the statutory provisions. If we do not conclude an employment contract with the applicant, the application documents will be deleted no later than six months after notification of the rejection decision, provided that no other legitimate interests on our part prevent deletion. Other legitimate interests in this sense include, for example, the burden of proof in proceedings under the General Equal Treatment Act (AGG).
2.6. Cookies
Our websites do not currently use cookies. Cookies do not harm your computer and do not contain viruses. Cookies serve to make our website more user-friendly, effective, and secure. Cookies are small text files that are sent from our web server to your browser when you visit our websites and are stored on your computer for later retrieval. They serve to make the Internet offering more user-friendly and effective overall.
2.7 Linking to Facebook
Our website links to services of the social network facebook.com, which is operated by Facebook Inc, 1601 S. California Ave, Palo Alto, CA 94304, USA. No data is transferred to Facebook when you visit our website, as no Facebook plug-ins are integrated. However, clicking on a Facebook link or Facebook button will take you to Facebook, where data will be collected by Facebook. The purpose and scope of the data collection and the further processing and use of the data by Facebook as well as your rights in this regard and setting options to protect your privacy can be found in Facebook’s data protection information and our data protection declaration for the Facebook fan page. If you are a Facebook member and do not want Facebook to collect data about you and link it to your membership data stored on Facebook, you must log out of Facebook before clicking on a Facebook link or a Facebook button.
2.8 Linking to Instagram
Functions of the Instagram service are integrated on our pages. These functions are offered by Instagram Inc, 1601 Willow Road, Menlo Park, CA, 94025, USA. If you are logged into your Instagram account, you can link the content of our pages to your Instagram profile by clicking on the Instagram button. This allows Instagram to associate your visit to our pages with your user account. We would like to point out that, as the provider of the pages, we have no knowledge of the content of the transmitted data or its use by Instagram. You can find more information on this in Instagram’s privacy policy: https://privacycenter.instagram.com/policy/