Privacy Policy

Your Data Is Safe

This privacy policy informs you of the nature, scope, and purpose of the processing of personal data (hereinafter referred to as "data") within our online offering and the associated websites, functions, and content, as well as external online presences, such as our social media profiles (hereinafter collectively referred to as the "online offering"). With regard to the terms used, such as "processing" or "controller," we refer to the definitions in Art. 4 of the General Data Protection Regulation (GDPR).

Data Controller

St. Jacobus Verwaltung GmbH
An der Gemeindewiese 5
09244 Lichtenau, Germany
E-mail address: info@sankt-jacobus.de

Link to the imprint: /imprint/

Categories of Data Processed:

– Inventory data (e.g., names, addresses).
– Contact data (e.g., email, phone numbers).
– Content data (e.g., text entries, photographs, videos).
– Usage data (e.g., websites visited, interest in content, access times).
– Meta/communication data (e.g., device information, IP addresses).

Categories of Data Subjects

Visitors and users of the online offering (hereinafter also referred to collectively as "users").

Purpose of Processing

– Provision of the online offering, its functions, and content.
– Responding to contact inquiries and communicating with users.
– Security measures.
– Reach measurement/marketing.

Terms Used

"Personal data" means any information relating to an identified or identifiable natural person (hereinafter "data subject"); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g. a cookie), or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.

"Processing" means any operation or set of operations which is performed on personal data, whether or not by automated means. The term is broad and covers virtually every handling of data.

"Pseudonymization" means the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures designed to ensure that the personal data are not attributed to an identified or identifiable natural person.

"Profiling" means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyze or predict aspects concerning that natural person's performance at work, economic situation, health, personal preferences, interests, reliability, behavior, location, or movements.

"Controller" means the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.

"Processor" means a natural or legal person, public authority, agency, or other body which processes personal data on behalf of the controller.

Relevant Legal Bases

In accordance with Art. 13 GDPR, we inform you of the legal bases for our data processing. Where the legal basis is not stated in the privacy policy, the following applies: the legal basis for obtaining consent is Art. 6(1)(a) and Art. 7 GDPR; the legal basis for processing to perform our services and carry out contractual measures, as well as to respond to inquiries, is Art. 6(1)(b) GDPR; the legal basis for processing to fulfill our legal obligations is Art. 6(1)(c) GDPR; and the legal basis for processing to safeguard our legitimate interests is Art. 6(1)(f) GDPR. In the event that the vital interests of the data subject or another natural person require the processing of personal data, Art. 6(1)(d) GDPR serves as the legal basis.

Security Measures

In accordance with Art. 32 GDPR, and taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, we take appropriate technical and organizational measures to ensure a level of protection appropriate to the risk.

These measures include, in particular, safeguarding the confidentiality, integrity, and availability of data by controlling physical access to the data, as well as access to, entry of, disclosure of, and the securing and separation of such data. Furthermore, we have established procedures to ensure the exercise of data subject rights, the erasure of data, and responses to data threats. In addition, we take the protection of personal data into account as early as the development or selection of hardware, software, and procedures, in accordance with the principle of data protection through technology design and through data-protection-friendly default settings (Art. 25 GDPR).

Cooperation with Processors and Third Parties

If, in the course of our processing, we disclose data to other persons and companies (processors or third parties), transfer it to them, or otherwise grant them access to the data, this is done only on the basis of a legal permission (e.g., if a transfer of data to third parties, such as payment service providers, is necessary pursuant to Art. 6(1)(b) GDPR for the performance of a contract), if you have consented, if a legal obligation provides for it, or on the basis of our legitimate interests (e.g., when engaging agents, web hosts, etc.).

If we commission third parties to process data on the basis of a so-called "data processing agreement," this is done on the basis of Art. 28 GDPR.

Transfers to Third Countries

If we process data in a third country (i.e., outside the European Union (EU) or the European Economic Area (EEA)), or if this occurs in the context of using third-party services or disclosing or transferring data to third parties, this is done only to fulfill our (pre-)contractual obligations, on the basis of your consent, due to a legal obligation, or on the basis of our legitimate interests. Subject to legal or contractual permissions, we process or have data processed in a third country only if the specific requirements of Art. 44 et seq. GDPR are met. This means that processing takes place, for example, on the basis of special safeguards, such as the officially recognized determination of a level of data protection equivalent to that of the EU (e.g., for the USA through the "Privacy Shield"), or compliance with officially recognized specific contractual obligations (so-called "standard contractual clauses").

Rights of Data Subjects

You have the right to request confirmation as to whether data concerning you is being processed, and to information about that data as well as further information and a copy of the data in accordance with Art. 15 GDPR.

In accordance with Art. 16 GDPR, you have the right to request the completion of data concerning you or the correction of inaccurate data concerning you.

In accordance with Art. 17 GDPR, you have the right to request that data concerning you be erased without delay, or, alternatively, in accordance with Art. 18 GDPR, to request a restriction of the processing of the data.

You have the right to request that the data concerning you that you have provided to us be handed over to you in accordance with Art. 20 GDPR and to request that it be transmitted to other controllers.

You further have the right, pursuant to Art. 77 GDPR, to lodge a complaint with the competent supervisory authority.

Right to Revoke Consent

You have the right to revoke consent already given, with effect for the future, pursuant to Art. 7(3) GDPR.

Right to Object

You may object at any time, pursuant to Art. 21 GDPR, to the future processing of data concerning you. The objection may be raised in particular against processing for direct marketing purposes.

Erasure of Data

The data we process is erased or its processing restricted in accordance with Art. 17 and 18 GDPR. Unless expressly stated within this privacy policy, the data stored with us is erased as soon as it is no longer required for its intended purpose and there are no legal retention obligations preventing its erasure. If the data is not erased because it is required for other legally permissible purposes, its processing is restricted. This means the data is blocked and not processed for other purposes. This applies, for example, to data that must be retained for commercial or tax law reasons.

Under German statutory requirements, retention periods are, in particular, 10 years pursuant to §§ 147(1) AO, 257(1) nos. 1 and 4, (4) HGB (books, records, management reports, accounting vouchers, commercial books, documents relevant for taxation, etc.) and 6 years pursuant to § 257(1) nos. 2 and 3, (4) HGB (commercial correspondence).

Under Austrian statutory requirements, retention periods are, in particular, 7 years pursuant to § 132(1) BAO (accounting records, receipts/invoices, accounts, vouchers, business papers, statements of income and expenses, etc.), 22 years in connection with real property, and 10 years for documents related to electronically supplied services and telecommunications, broadcasting, and television services provided to non-business customers in EU member states for which the Mini-One-Stop-Shop (MOSS) scheme is used.

Privacy Notices in the Application Process

We process applicant data only for the purpose and within the scope of the application process, in accordance with statutory requirements. Applicant data is processed to fulfill our (pre-)contractual obligations within the application process within the meaning of Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR, insofar as data processing becomes necessary for us, for example, in the context of legal proceedings (in Germany, § 26 BDSG additionally applies).

The application process requires applicants to provide us with their applicant data. Where we offer an online form, the necessary applicant data is marked accordingly; otherwise it follows from the job descriptions and generally includes personal details, postal and contact addresses, and the documents belonging to the application, such as cover letter, CV, and references. In addition, applicants may voluntarily provide us with additional information.

By submitting their application to us, applicants consent to the processing of their data for the purposes of the application process in the manner and to the extent set out in this privacy policy.

Insofar as special categories of personal data within the meaning of Art. 9(1) GDPR are voluntarily disclosed in the course of the application process, their processing additionally takes place pursuant to Art. 9(2)(b) GDPR (e.g., health data, such as severe disability status or ethnic origin). Insofar as special categories of personal data within the meaning of Art. 9(1) GDPR are requested from applicants in the course of the application process, their processing additionally takes place pursuant to Art. 9(2)(a) GDPR (e.g., health data, where required for the performance of the job).

Where made available, applicants may submit their applications to us via an online form on our website. The data is transmitted to us encrypted in accordance with the state of the art.
Applicants may also submit their applications to us via email. Please note, however, that emails are generally not sent encrypted, and applicants themselves are responsible for encryption. We can therefore accept no responsibility for the transmission path of the application between the sender and receipt on our server, and therefore recommend using an online form or postal mail instead. Instead of applying via the online form or email, applicants also have the option of sending their application to us by post.

Data provided by applicants may, in the event of a successful application, be further processed by us for the purposes of the employment relationship. Otherwise, if an application for a job posting is unsuccessful, the applicant's data is erased. Applicant data is likewise erased if an application is withdrawn, which applicants are entitled to do at any time.

Application Process via Job Postings

  1. We use the job posting and applicant management software of On-apply GmbH to optimize our recruitment processes. Should you apply to us, we process, for this purpose, the data you provide to us in the course of the application process.
  2. The legal basis for this is Art. 88 GDPR in conjunction with § 26 BDSG, as well as Art. 6(1)(b) GDPR for the initiation of contractual relationships. Should an employment relationship arise between you and us, we subsequently process the personal data already received from you for the purpose of the employment.
  3. Insofar as you have additionally given explicit consent in your application to extended storage in an applicant tool, the duration of processing extends over that period. Consent given may be revoked at any time, with effect for the future, by sending us a message.
  4. Data is erased after six months, provided there are no legal retention obligations and no overriding interests worthy of protection.

Erasure takes place, subject to a legitimate revocation by applicants, after a period of six months has elapsed, so that we can answer any follow-up questions regarding the application and meet our documentation obligations under the Equal Treatment Act. Invoices for any travel expense reimbursement are archived in accordance with tax law requirements.

Contact

When you contact us (e.g., via contact form, email, telephone, or social media), the user's details are processed for the purpose of handling and following up on the contact request pursuant to Art. 6(1)(b) GDPR (within the context of contractual/pre-contractual relationships) and Art. 6(1)(f) GDPR (other inquiries). User details may be stored in a customer relationship management system ("CRM system") or a comparable inquiry organization system.

We erase inquiries once they are no longer required. We review the necessity every two years; furthermore, statutory archiving obligations apply.

Hosting and Email Dispatch

The hosting services we use serve to provide the following services: infrastructure and platform services, computing capacity, storage space and database services, email dispatch, security services, and technical maintenance services, which we use for the purpose of operating this online offering.

In doing so, we, or our hosting provider, process inventory data, contact data, content data, contract data, usage data, and meta and communication data of customers, prospective customers, and visitors to this online offering on the basis of our legitimate interest in an efficient and secure provision of this online offering pursuant to Art. 6(1)(f) GDPR in conjunction with Art. 28 GDPR (conclusion of a data processing agreement).

Collection of Access Data and Log Files

We, or our hosting provider, collect data on the basis of our legitimate interests within the meaning of Art. 6(1)(f) GDPR on every access to the server on which this service is located (so-called server log files). Access data includes the name of the website accessed, file, date and time of access, amount of data transferred, notification of successful access, browser type and version, the user's operating system, referrer URL (the previously visited page), IP address, and the requesting provider.

Log file information is stored for security reasons (e.g., to investigate abuse or fraud) for a maximum of 7 days and then erased. Data whose further retention is required for evidentiary purposes is exempt from erasure until the respective incident has been finally resolved.

Created with Datenschutz-Generator.de by RA Dr. Thomas Schwenke