- Information on the processing of customer / prospects / supplier data
- Information on the processing of applicant data
Information on the processing of customer / prospects / supplier data
KUMAVISION AG takes the protection of your personal data very seriously. Your privacy is important for us. We process your personal data in accordance with the applicable, legal, data protection requirements for the purposes listed below. Personal data within the meaning of this data protection information includes all the information that relates to your person.
In the following, you want to learn how we handle this data. For a better overview, we have divided our data protection into chapters.
Responsible Body and Data Protection Officer
Responsible for the data processing is:
88677 Markdorf (Lake Constance)
Tel.: + 49 7544 966-300
Fax: + 49 (7544) 966-101
Should you have any questions or comments concerning data protection (for example, information on / updating your personal data), you can also contact our Data Protection Officer:
German Data Protection Law Office - Maximilian Musch
88094 top rings
Tel .: + 49 (7544) 9049691
2 processing scope
2.1 Source for the data collection
We process personal data that we have gathered directly from you.
Insofar as this is necessary for the provision of our services, we process rightfully-obtained, personal data from other companies or other third parties (eg, credit bureaus, address publishers). In addition, we process personal data which has been obtained, such as for example, telephone directories, commercial and association registers, civil registers, debtor directories, country registers, the press, Internet and other media ), and are allowed to process.
2.2 Origin and data categories of data not directly collected from you
Insofar as this is necessary for the provision of our services, we process rightfully-obtained, personal data from other companies or other third parties. In addition, we process personal data which have been obtained, received or received from the available sources (the press, Internet and other media), and are allowed to process. Relevant personal-data categories may be in particular:
- Personal data (name, function in the company and comparable data)
- Contact details (addresses, email addresses, telephone numbers and comparable data)
- ata concerning your use of the telemedia offered by us (eg time of call-up of our websites, apps or newsletters, our clicked-on pages / links, or entries and comparable data)
2.3 Purposes and legal basis of the data processed
We process personal data in accordance with the provisions of the Basic Data Protection Regulation (GDPR), the new version of the Federal Data Protection Act (BDSG-new), and other applicable data-protection regulations (see details below). The data that is processed in detail and how it is dealt with, is primarily determined by the respective services requested or agreed upon. For further details or additions to the purposes of the data processing, please refer to the respective contract documents, forms, a declaration of consent and / or other information provided to you (eg in connection with the use of our website or our terms and conditions) ).
Purposes of a contract or implementing pre-contractual measures (Art. 6 para. 1 b DSGVO)
The processing of personal data is carried out in the framework of pre-contractual relationships, eg with interested parties. This includes in essence: the contract-related communication with you, the corresponding billing and related payment transactions, the verifiability of orders and other agreements, as well as the quality control using appropriate documentation, goodwill procedures, measures for controlling and optimizing business processes, and in order to fulfill the general due diligence obligations, the management and control by affiliated companies; statistical evaluations for corporate management, cost accounting and controlling, reporting, internal and external communication, emergency management, settlement and tax assessment of operating services, risk management, assertion of legal claims and the defense in the case of legal disputes; ensuring IT security (including system and plausibility tests) and the general security, ensuring and exercising the domiciliary rights (eg through access controls); Ensuring the integrity, availability, and availability of the data.
Purposes within the framework of a legitimate interest in our part or third parties (Art. 6 para. 1 f DSGVO)
In addition to the actual fulfillment of the contract or the preliminary contract, we may process your data, if it is necessary, for protecting our legitimate interests or those of third parties, in particular for purposes regarding
- advertising or market and opinion research, insofar as you have not objected to the use of your data;
- the testing and optimization of procedures for needs analysis;
- the further development of services and products, as well as existing systems and processes;
- the enrichment of our data, generally through the use or search of publicly available data;
- statistical evaluations or the market analysis; benchmarking;
- the assertion of legal claims and defense in the case of legal disputes which are not
- directly attributable to the contractual relationship;
- the limited storage of the data, if it is not possible due to the specific nature of the storage or disproportionately high expenditure;
- the prevention and investigation of criminal offense, if not exclusively for the fulfillment of legal requirements
- the safety of buildings and plants, in the event of exceeding the general due diligence obligations;
- internal and external investigations, as well as security audits; possible monitoring or
- the acquisition and maintenance of a private or regulatory nature;
- the safeguarding and observance of the domiciliary rights by means of appropriate measures (such as video surveillance), and for safeguarding evidence in the event of criminal offense and their prevention.
Purposes within the framework of your consent (Art. 6 para 1a DSGVO)
The processing of your personal data for specific purposes may also be carried out on the basis of your consent. As a rule, you can revoke this at any time. This is applies to the validity of the DSGVO, ie before 25th May 2018. You will be informed separately in the corresponding text of the consent, of the purposes and the consequences of a withdrawal or the non-granting thereof. As a general rule, the withdrawal of a consent is effective only for the future. Any processing carried out prior to the event shall not be affected and remains lawful.
Purposes for fulfilling legal requirements (Art. 6 para. 1 c DSGVO (GDPR)) or in the public interest (Art. 6 para. 1 e DSVGO)
In the same way as for anyone involved in business, we are too, so are subject to a large number of legal obligations. These are primarily legal requirements (eg commercial and tax laws), but regulatory or other official requirements, if applicable. The purposes of processing may include the fulfillment of tax and reporting obligations, and thus the archiving of data for data protection and data security purposes, as well as audits by tax and other authorities. In addition, the disclosure of personal data in the context of administrative / judicial action may be required for the purposes of gathering evidence, prosecuting or enforcing civil claims.
Extent of your duties to provide us with data
A pre-contractual relationship with us, or for the collection of which we are bound by law.
As a rule, we are unable to conclude or execute the contract without this data. This may apply to data required later in the business relationship. Should we request further data from you, you will be notified of the voluntary nature of the information.
Existence of an automated, decision-making procedure in an individual case (including profiling)
Pursuant to Article 22 DSVGO, we do not use fully automated, decision-making procedures. Should we use a procedure of this child in individual cases in the future, we shall inform you separately, insofar as this is required by law. If need be, we may process your information partially, with the aim of evaluating certain personal aspects (profiling).
In may be used to provide you with targeted product information and advice. These enable a requirement-oriented product design, communication and advertising, including market and opinion research. Pursuant to Art. 9 DSVGO, data on nationality and specific categories of personal data are not processed.
2.4 Consequences of failure to provide data
Within the framework of the business relationship, you are required by law to collect. Without this data, we shall not be able to conduct the transaction with you.
2.5 Recipients of the data within the EU
Within our company, they are responsible for the fulfillment of their contractual obligations.
A transfer of your data to external agencies is carried out exclusively
- in connection with the execution of the contract;
- for the purpose of providing legal requirements, in accordance with which we provide information, notification or the disclosure of data, or pass on data in the public interest (see Section 2.4);
as a processor or subcontractor (eg computer centers, support / maintenance of EDP / IT applications, archiving, document processing, call-center services, compliance services, controlling, data validation or plausibility check, data destruction, purchasing / procurement, customer administration, letter shops, marketing, media technology, research, risk controlling, billing, telephony, website management, auditing services, credit institutions, printers or companies for data disposal, courier services, logistics);
- on the basis of the legitimate interests of the third party, in the context of the stated purposes (eg, to offices, credit bureaus, debt collection agencies, lawyers, courts, appraisers, subsidiaries, committees and supervisory bodies);
- if you have given us your consent for transmission to third parties.
We would not otherwise pass on your data to third parties. Insofar as we commission service providers within the scope of processing order, your data will then be subject to the same security standards as with us. In all other cases, the recipients may only use the data for the purposes for which they were transmitted to them.
2.6 Recipients of the data outside the EU
A transfer of data to agencies outside the European Union (EU) or the European Economic Area (EEA), is carried out if it is necessary for executing an order / contract by, or with you, if it is required by law, if it is within the scope of a legitimate interest of ours or a third party, or if you have given us your consent.
In this case, the processing of your data in a third country may also be carried out in conjunction with the involvement of service providers within the scope of the order processing. There is no guarantee that the data will be protected by law. We guarantee compliance with the EU data-protection stipulations, that the rights and freedoms are adequately protected and guaranteed by appropriate contracts , Relevant detailed information is available upon request. The data protection officer may request information on whether or not to obtain a copy of the data.
2.7 Data retention periods
We process and store your data for the duration of our business relationship. This also includes the initiation of a contract and the execution of a contract.
In addition, we are subject to various storage and documentation obligations, set out in the Commercial Register (HGB) and the Tax Code (AO) ia. The deadlines for the storage and / or documentation are the same as those at the end of the calendar year.
Furthermore, specific legal requirements may require a longer period of time; Pursuant to §§ 195 ff. Of the German Civil Code (BGB), the regular period of limitation is three years; however, limitation periods of up to 30 years may be applicable.
Should the data no longer be required for the fulfillment of the contractual or legal obligations and rights; It is therefore possible to give or not to disproportionately high expenditures and processing for other purposes, using appropriate technical and organizational measures excluded.
2.8 Your rights
Under certain conditions you may assert your data protection rights vis-à-vis us.
- 15 DSGVO (GDPR) (possibly with restrictions in accordance with Section 34 BDSG (Federal Data Protection Act)).
- 16 DSGVO (GDPR), they should be inappropriate or incorrect.
- If you wish, we shall delete your data in accordance with the principles of Art. 17 DSGVO (GDPR), provided that no other legal regulations or regulations are in compliance with § 35 BDSG part (eg for defending our rights and claims).
- Considering the requirements of Art. 18 DSGVO (GDPR), you may require to restrict the processing of your data.
- Furthermore, you may object to the processing of your data in accordance with Art. 21 DSGVO (GDPR) which requires us to stop processing your data. However, this right of objection only applies in the case of your personal situation, which is the right of objection.
- 20 DSGVO (GDPR) in a structured, common and machine-readable format, or to transmit them to a third party.
- In addition, you have the right to withdraw your consent for the processing of personal data at any time, with future effect (Comp. Section 2.3).
- Furthermore, you have a right to appeal to a data protection supervisory authority (Art. 77 DSVGO (GDPR)). However, we always recommend that you file a complaint with our Data Protection Officer first.
- Your requests for exercising your rights should, where possible, be addressed in writing or by email to the address given above, or directly in writing or by email to our Data Protection Officer.
Special reference to your right of objection under Art. 21 DSGVO (GDPR)
You have the right to object at any time to the processing of your data, which is carried out on the basis of Art. 6 para. 1 f DSGVO (GRPR) (Data processing on the basis of a balance of interest) or Art. 6 para. 1 e DSGVO (GDPR) (data processing in the public interest), if there are reasons for this emergence from your particular situation.
4 no. 4 DSGVO. If you object, we will no longer process your personal information, unless we can provide you with the legal grounds for the processing that are outweigh your interests, or freedoms, or the processing serves the purpose of asserting, exercising or defending legal claims.
If necessary, we process your personal data in order to conduct direct advertising. If you do not wish to receive any advertising, you have the right to file an objection to it at any time; this so applies to profiling, insofar as it is associated with direct advertising of this child. We shall take this objection into account for the future. We shall no longer process your data for direct advertising purposes.
The objection can be filed without observing any formal requirements, and should be addressed, as far as possible, to:
88677 Markdorf (Lake Constance)
Tel.: + 49 7544 966-300
Fax: + 49 (7544) 966-101
State Representative for Data Protection and Freedom of Information Baden-Württemberg (State Representative for Data Protection and Freedom of Information)
Lautenschlagerstrasse 20, 70173 Stuttgart
Postbox 10 29 32, 70025 Stuttgart
Phone: 0711 / 615541-0
Fax: 0711 / 615541-15
Information on the processing of applicant data
We are pleased that you are interested in us, and that you have applied or are applying for a position in our company. We would like to provide you with the following information on the processing of your personal data in connection with your application.
Who is responsible for data processing?
Tel: 07544 966-403
Fax: 07544 966-101
You will find more information about our company, and details on the persons authorized to represent us, as well as further contact options, in the imprint on our website.
Which of your data are processed by us? And for what purposes?
We process the information you have provided in your application, in order to assess your suitability for the position (or, if applicable, for other open positions in our companies) and to carry out the application process.
On what legal basis is this processing carried out?
The legal basis for the processing of your personal data in this application process is § 26 Federal Data Protection Act (BDSG) in the version valid as from 25.05.2018. Accordingly, the processing of the data required in connection with the decision to establish employment relationship, is permitted.
6 DSGVO (GDPR), in particular for exercising legitimate interests in accordance with Art. 6 para. 1 f DSGVO (GDPR) may be carried out. Our interest then reads in the assertion of, or defense against claims.
For how long is the data stored?
In the case of cancellation, the applicant's data is deleted after 6 months. In the event of you having consented to the further storage of your personal data, we would like to transfer your data to our applicant pool. The data is deleted after two years. Should have been awarded the contract as part of the application process?
To which recipients does the data be passed on?
We use a specialized software provider for the application process. This person acts as a service provider and, in connection with the maintenance and care of the systems, may therefore be aware of your personal data. We have concluded an order-processing contract with this provider, which ensures that the data processing takes place in a permissible manner.
Your application data will be viewed by the Personnel Department upon receipt of your application. Suitable applications are then forwarded internally to the department heads for the respective open position in each case. The further procedure is then coordinated. In principle, only the persons in the company, who need your data for the proper execution of our application process, have access to it.
Where is the data processed?
The data is processed exclusively in data centers of the Federal Republic of Germany.
Your rights as "the person concerned"
You have the right to obtain information about the personal data processed by us about you. In the case of a request for information that is not written in writing, we ask for your understanding.
Furthermore, you have the right to request rectification, deletion or restriction of the processing, as far as you are legally entitled to do so.
Furthermore, you have the right to object to the processing, within the scope of the legal requirements. The same applies to a data portability.
The revocation must be sent by post to the Personnel Department or by email to:
Our Data Protection Officer
We have a Data Protection Officer in our company. You can reach him under the following contact options:
German Data Protection Law Firm
Tel: 07544 904 96 91
Right of appeal
You have the right to complain to the competent authority for data protection, regarding the processing of personal data by us.