Data Protection
We, RAICO Bautechnik GmbH, are the data controller for this website and, as a provider of a teleservice, are required to inform you at the start of your visit to our website about the nature, scope and purposes of the collection and use of personal data in a precise, transparent, comprehensible and easily accessible form, using clear and simple language. The content of this information must be accessible to you at all times. We are therefore obliged to inform you which personal data is collected or used. Personal data refers to any information relating to an identified or identifiable natural person.
We attach the utmost importance to the security of your data and compliance with data protection regulations. The collection, processing and use of personal data are subject to the provisions of the currently applicable European and national laws.
With the following privacy policy, we would like to explain how we handle your personal data and how you can contact us.
We have appointed a Data Protection Officer for our company, whom you can contact with any queries as follows:
Anwaltskanzlei Schenk Datenschutz Rechtsanwaltsgesellschaft mbH
Auf der Wies 18
87727 Babenhausen
Telephone +49 8333 9269 360
Fax +49 8333 9269 361
Email datenschutz(at)europajurist-schenk.com
Website www.europajurist-schenk.com
A. General
For the sake of clarity, our privacy policy does not make any gender-specific distinctions. In the interests of equal treatment, the relevant terms apply to both genders.
The meanings of the terms used, such as ‘personal data’ or ‘processing’, can be found in Article 4 of the EU General Data Protection Regulation (GDPR).
The personal data of users processed within the scope of this online service includes master data (e.g. names and addresses of customers), contractual data (e.g. services used, names of case handlers, payment information), usage data (e.g. pages visited on our website, interest in our products) and content data (e.g. entries in the contact form).
‘Users’ here refers to all categories of data subjects affected by data processing. These include, for example, our business partners, customers, prospective customers and other visitors to our online service.
B. Specific
Privacy Policy
We guarantee that we collect, process, store and use your data solely in connection with the handling of your enquiries, for internal purposes, and to provide the services or content you have requested.
Basis for data processing
We process users’ personal data only in compliance with the relevant data protection regulations. This means that users’ data is processed only where there is a legal basis for doing so, namely:
- to provide our contractual services (e.g. processing orders), or where this is required by law,
- where you have given your consent, as well as
- on the basis of our legitimate interests (i.e. our interest in the analysis, optimisation, economic operation and security of our online service within the meaning of Article 6(1)(f) of the GDPR, in particular with regard to audience measurement, the creation of profiles for advertising and marketing purposes, as well as the collection of access data and the use of third-party services).
We would like to show you where the above legal bases are set out in the GDPR:
Consent: Art. 6 par. 1 lit. a. and Art. 7 GDPR
processing for the fulfilment of our services and the im-plementation of contractual measures: Art. 6 par. 1 lit. b GDPR
Processing for the fulfilment of our contractual obligations: Art. 6 par. 1 lit. c GDPR
Processing for the protection of our legitimate interests: Art. 6 par. 1 lit. f GDPR
Data transfer to third parties
Data is only disclosed to third parties in accordance with legal requirements. We only disclose users’ data to third parties if this is necessary, for example, for contractual purposes or on the basis of legitimate interests in the economic and effective operation of our business.
Where we engage subcontractors to provide our services, we take appropriate legal precautions and implement corresponding technical and organisational measures to ensure the protection of personal data in accordance with the relevant legal provisions.
Data transfer to a third country or an international organisation
A ‘third country’ refers to countries in which the GDPR is not directly applicable. This generally includes all countries outside the EU or the European Economic Area.
No data is transferred to a third country.
Retention period for your personal data
We adhere to the principles of data minimisation and data avoidance. This means that we only store the data you provide to us for as long as is necessary to fulfil the aforementioned purposes or as stipulated by the various retention periods laid down by law. Once the relevant purpose no longer applies, or upon expiry of the relevant retention periods, your data will be routinely blocked or deleted in accordance with statutory provisions.
To this end, we have drawn up an internal company policy to ensure this procedure is followed.
Contacting RAICO Bautechnik GmbH
If you contact us by email or via the contact form, you consent to electronic communication. Personal data is collected when you contact us. The data collected via a contact form is specified on the relevant contact form. Your data is transmitted securely (using SSL encryption). The information you provide is stored solely for the purpose of processing your enquiry and for any follow-up questions.
We would be happy to provide you with the legal bases for this:
Processing to fulfil our services and carry out contractual measures: Article 6(1)(b) of the GDPR
Processing to safeguard our legitimate interests: Article 6(1)(f) of the GDPR
We use software for managing customer data (CRM system) or similar software on the basis of our legitimate interests (efficient and rapid processing of user enquiries).
We would like to draw your attention to the fact that emails may be read or altered without authorisation and without your knowledge whilst in transit. Furthermore, we would like to draw your attention to the fact that we use software to filter out unwanted emails (spam filter). The spam filter may block emails if they are incorrectly identified as spam due to certain characteristics.
What rights do you have?
a) Right of access
You have the right to obtain information about your stored data free of charge. Upon request, we will inform you in writing, in accordance with applicable law, of the personal data we hold about you. This also includes the source and recipients of your data, as well as the purpose of the data processing.
b) Right to rectification
You have the right to have your data stored by us rectified if it is inaccurate. In this context, you may request a restriction on processing, e.g. if you dispute the accuracy of your personal data.
c) Right to restriction of processing
Furthermore, you may have your data restricted. To ensure that the blocking of your data can be implemented at any time, this data must be retained in a blocking file for monitoring purposes.
d) Right to erasure
You may also request the erasure of your personal data, provided there are no statutory retention obligations. Where such an obligation exists, we will block your data upon request. If the relevant legal requirements are met, we will delete your personal data even without a specific request from you.
e) Right to data portability
You are entitled to request that we provide you with the personal data you have submitted to us in a format that allows it to be transferred to another organisation.
f) Right to lodge a complaint with a supervisory authority
You have the option of lodging a complaint with one of the data protection supervisory authorities.
Bavarian State Office for Data Protection Supervision (BayLDA)
Promenade 27, D-91522 Ansbach
Telephone: +49 981 53-1300
Fax: +49 981 53-981300
You can access the Bavarian State Office for Data Protection Supervision’s complaint form via the following link:
https://www.lda.bayern.de/de/beschwerde.html
g) Right to object
You may at any time withdraw your consent to the use of your data for internal purposes with effect for the future. To do so, simply send an email to datenschutz(at)europajurist-schenk.com. However, such a withdrawal does not affect the lawfulness of any processing carried out by us up to that point. Data processing based on all other legal grounds, such as the initiation of a contract (see top), remains unaffected.
Protection of your personal data
We implement contractual, organisational and technical security measures in line with the state of the art to ensure compliance with data protection legislation and thereby protect the data we process against accidental or deliberate manipulation, loss, destruction or access by unauthorised persons.
These security measures include, in particular, the encrypted transmission of data between your browser and our server. A 128-bit SSL (AES 128) encryption technique is used for this purpose. This includes your IP address.
In doing so, your personal data is protected in accordance with the following points (excerpt):
a) Safeguarding the confidentiality of your personal data To safeguard the confidentiality of your personal data stored with us, we have implemented various measures for access control.
b) Safeguarding the integrity of your personal data To safeguard the integrity of your personal data stored with us, we have implemented various measures for data transfer and input control.
c) Safeguarding the availability of your personal data
To ensure the availability of your personal data stored with us, we have implemented various measures for job and availability control.
The security measures in place are continuously improved in line with technological developments. Despite these precautions, due to the insecure nature of the internet, we cannot guarantee the security of your data transmission to our online service. Consequently, any data transmission from you to our online service is at your own risk.
Protection of minors
Persons who have not yet reached the age of 16 may not provide us with any personal data without the consent of their legal guardians. Persons under the age of 16 may only provide us with personal information if they have the express consent of their legal guardian or if they are aged 16 or over. This data will be processed in accordance with this privacy policy.
Protection of Minors
Individuals under the age of 18 must not provide us with any personal data without the consent of their legal guardians. Personal information may only be provided to us by individuals under the age of 18 if the express consent of their legal guardians has been obtained. This data will be processed in accordance with this Privacy Policy.
Whistleblower
We use the information you provide via the whistleblower system, amongst other things, for the purpose of verifying and documenting reports, for internal investigations and, where necessary, for disclosure to public authorities (such as the police, the public prosecutor’s office or the courts). We guarantee that all whistleblowers’ information will be treated confidentially. The legal basis is the fulfilment of legal obligations pursuant to Article 6(1)(c) of the GDPR.
Google Tag Manager
We use Google Tag Manager. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Tag Manager is a tool that enables us to integrate tracking or analytics tools, as well as other technologies, into our website. Google Tag Manager itself does not create user profiles, store cookies or carry out independent analyses. It serves solely to manage and execute the tools integrated via it. However, Google Tag Manager does collect your IP address, which may also be transmitted to Google’s parent company in the United States.
The use of Google Tag Manager is based on Article 6(1)(f) of the GDPR. The website operator has a legitimate interest in the quick and straightforward integration and management of various tools on its website. Where the relevant consent has been obtained, processing takes place exclusively on the basis of Article 6(1)(a) of the GDPR and Section 25(1) of the TDDDG, insofar as the consent covers the storage of cookies or access to information on the user’s device (e.g. device fingerprinting) within the meaning of the TDDDG. This consent may be withdrawn at any time.
The company is certified under the ‘EU-US Data Privacy Framework’ (DPF). The DPF is an agreement between the European Union and the USA designed to ensure compliance with European data protection standards when processing data in the USA. Every company certified under the DPF has an obligation to comply with these data protection standards. Further information is available from the provider via the following link: Data Privacy Framework.
Google Analytics
This website uses features of the web analytics service Google Analytics. The provider of this service is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland. Google Analytics enables the website operator to analyse the behaviour of website visitors. To this end, the website operator receives various usage data, such as the pages visited, the time spent on the site, the operating system used and the user’s origin. This data is aggregated into a user ID and assigned to the website visitor’s respective device.
Furthermore, Google Analytics enables us, amongst other things, to track your mouse and scroll movements as well as your clicks. Google Analytics uses various modelling approaches to supplement the collected data sets and employs machine learning technologies in its data analysis.
Google Analytics uses technologies that enable the user to be recognised for the purpose of analysing user behaviour (e.g. cookies or device fingerprinting). The information collected by Google regarding the use of this website is generally transmitted to a Google server in the United States and stored there.
The use of these services is based on your consent in accordance with Article 6(1)(a) of the GDPR and Section 25(1) of the TDDDG. You may withdraw your consent at any time.
Data is transferred to the USA on the basis of the European Commission’s Standard Contractual Clauses (SCCs). Further details can be found here: https://privacy.google.com/businesses/controllerterms/mccs/.
The company is certified under the ‘EU-US Data Privacy Framework’ (DPF). The DPF is an agreement between the European Union and the US designed to ensure compliance with European data protection standards when processing data in the US. Every company certified under the DPF has an obligation to comply with these data protection standards. Further information is available from the provider via the following link: Data Privacy Framework.
Changes to our Privacy Policy
We reserve the right to amend our Privacy Policy from time to time to ensure it always complies with current legal requirements or to reflect changes to our services in the Privacy Policy. This could, for example, relate to the introduction of new services. The new Privacy Policy will then apply for your next visit.
Obligation to provide information when data is collected directly:
Privacy Notice for Prospective Customers, Customers and Suppliers
Privacy Notice for Job Applicants