PRIVACY NOTICE

As the data controller we have prepared this privacy notice to inform you in accordance with the requirements of the EU General Data Protection Regulation 2016/679 (GDPR) about the nature, scope and purpose of the processing of personal data in relation to the services we offer on our web site. 

1. DEFINITIONS

"Personal data“ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;

“Data subject” means any identified or identifiable natural person whose personal data is processed by the controller;

"Processing“ means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;

“Restriction of the processing” means the marking of stored personal data with the aim to limit their future processing;

“Profiling” is any kind of automated processing of personal data that consists in using that personal information to evaluate certain personal aspects relating to a natural person, in particular to analyze or predict aspects relating to job performance, economic situation, health, personal preferences interests, reliability, behavior, whereabouts or relocation of that natural person.

“Pseudonymisation” is the processing of personal data in such a way that personal data can no longer be attributed to a specific data subject without the need for additional information, provided that such additional information is kept separate and is subject to technical and organizational measures to ensure that the personal data can’t be attributed to an identified or identifiable natural person;

"Controller“ means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law;

“The processor” is a natural or legal person, public authority, institution or other entity that processes personal data on behalf of the controller;

„Recipient“ means a natural or legal person, public authority, agency or another body, to which the personal data are disclosed, whether a third party or not. However, public authorities which may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients; the processing of those data by those public authorities shall be in compliance with the applicable data protection rules according to the purposes of the processing;

“Third party” means a natural or legal person, public authority, institution or other entity other than the data subject, the controller, the processor and the persons authorized under the direct responsibility of the controller or the processor to process the personal data;

“Consent” means any voluntarily given and unambiguously expressed declaration of intention in the form of a statement or other unambiguous confirmatory act by the data subject for the particular case, by which the data subject indicates the consent to the processing of the personal data concerning him / her.

II. General information

1.    The data controller
MPS Bauplanung GmbH
Winfried Mayer Dipl.-Ing. (FH)
Rutesheimer Str. 24
70499 Stuttgart
Deutschland
Tel.: 0049 711 1399 650
E-Mail: stuttgart@mps-bauplanung.de
Website: www.mps-bauplanung.de

2.    Contact details of the data protection officer
We have not nominated a data protection officer nor are we obliged to appoint one.


3.    Legal bases
We process personal data based on at least one of the following legal bases:

-    The data subject has given consent to the processing of his or her personal data for one or more specific purposes (Art.  6 para. 1 lit. a GDPR);
-    Processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract (Art.  6 para. 1 lit. b GDPR);
-    Processing is necessary for compliance with a legal obligation to which we are subject (Art.  6 para. 1 lit. c GDPR);
-    Processing is necessary in order to protect the vital interests of the data subject or of another natural person (Art.  6 para. 1 lit. d GDPR);
-    Processing is necessary for the purposes of the legitimate interests pursued by us or by a third party (Art.  6 para. 1 lit. f GDPR)

In this privacy policy we refer to the respective legal basis of the individual data processing operations.

4.    Onward transfer of personal data
We forward personal data to recipients (data processors or other third parties) only to the extent required and only if one of the subsequent conditions are met:

-    the data subject has consented to the data transfer;
-    the onward transfer is required to fulfil a contractual obligation or pre-contractual measure on the request of the data subject;
-    we are obliged by law to make such a transfer;
-    The onward transfer is made on the basis of our legitimate interest or on those of a third party.

5.    Third countries
The transfer of personal data to a third country or an international organisation outside the European Union (EU) or the European Economic Area (EEA) is subject to legal or contractual permission only in accordance with the provisions under Art. 44 et seq. GDPR. It means that pursuant to Art. 45 GDPR an adequacy decision of the EU commission must be present for the respective country, appropriate safeguards for data privacy under Art. 46 GDPR, or Binding Corporate Rules under Art. 47 GDPR do exist. In individual cases, a data transfer may be permitted on the basis of an exception under Art. 49 GDPR.
We may use on our website external services provided by organisations based in the USA. If these services are active, personal data is collected in connection with the provision of the relevant service and may be transferred to and stored on servers in the USA. The European Court of Justice considers the USA to have an inadequate level of data protection. When data is transferred to the US, there is a fundamental risk that the US authorities may access and use the data for surveillance and monitoring purposes without notification and without the possibility of a legal remedy.

6.    Rights of data subjects
As a data subject you have the following right:

-    Pursuant to Art. 15 GDPR to request information about your personal data processed by us. You may also request information regarding the purposes of the processing; the categories of personal data concerned; the recipients or categories of recipients to whom the personal data have been or will be disclosed; the envisaged period for which the personal data will be stored, or the criteria used to determine that period; where the personal data are not collected from you, the data source; the existence of automated decision-making, including profiling, and meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing; the existence of the right to request rectification or erasure of data concerning you, the right to restrict processing or to object to such processing, the right to lodge a complaint with a supervisory authority. Finally, you have a right to know whether personal data has been transferred to a third country or to an international organisation, and, if so, the appropriate safeguards relating to this transfer;

-    Pursuant to Art. 16 GDPR to demand the immediate rectification of inaccurate personal data and to have incomplete personal data that are stored by us to be completed;

-    Pursuant to Art. 17 GDPR to demand the erasure of your personal data stored by us, unless the processing is necessary for exercising the right of freedom of expression and information, for compliance with a legal obligation, for reasons of public interest, or for the establishment, exercise or defence of a legal claim;

-    Pursuant to Art. 18 GDPR to request the restriction of the processing of your personal data if the accuracy of the personal data is contested by you; the processing is unlawful but you oppose the erasure of the personal data and request the restriction of their use instead; we no longer need the personal data for the purposes of the processing, but they are required by you for the establishment, exercise or defence of legal claims; you have objected to processing pursuant to Art. 21(1) GDPR pending the verification whether our legitimate grounds override your interests;

-    Pursuant to Art. 20 GDPR to receive your personal data, which you have provided to us, in a structured, commonly used and machine-readable format and have the right to transmit those data to another controller;

-    Pursuant to Art. 21 GDPR to object to the processing of your personal data on grounds relating to your particular situation, or if you object to processing for direct marketing purposes and the legal basis for the processing are our legitimate interests pursuant to Art. 6 para. 1 lit. f GDPR;

-    Pursuant to Art. 7 para. 3 GDPR to withdraw your consent given to us at any time. As a result we are no longer allowed to continue the data processing that was based on this consent in the future;

-    Pursuant to Art. 77 GDPR to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement. A list of contact details of the data protection officers and supervisory authorities can be found on this web site: https://www.bfdi.bund.de/DE/Infothek/Anschriften_Links/anschriften_links-node.html.

If you wish to assert the data subject rights mentioned above, you can contact us at any time using the contact details above.

7.    Erasure and restriction of personal data
Unless otherwise provided for in this privacy notice, personal data will be deleted, if these data are no longer necessary in relation to the purposes for which they were collected or otherwise processed and the deletion does not conflict with statutory retention requirements. In addition, we will erase the personal data processed by us in accordance with Art. 17 GDPR on your request, if the conditions provided therein are met. If personal data are required for other lawful purposes, they will not be erased, but their processing will be restricted in accordance with Art. 18 GDPR.
In case of restriction, the data will not be processed for other purposes. This applies, for example, to personal data that must be retained by us for commercial or tax law reasons. For example, data must be kept for 6 years pursuant to Section 257 (1) Nos. 2 and 3 German Commercial Code (HGB) and Section 147 (1) Nos. 2, 3, 5 German Tax Code (AO); data must be kept for 10 years pursuant to Section 257 (1) Nos. 1 and 4 HGB and Section 147 Abs. 1 No. 1, 4, 4a AO.

8.    Cookies
Our web site uses cookies. Cookies are small text files that your browser automatically creates and stores on your device (laptop, tablet, smartphone, PC, etc.) when you visit our web site. Cookies do no harm to your device, nor do they contain any viruses or other malicious software. The cookie stores information which is created in relation to the specific device you are using. However, this does not mean that we become immediately aware of your identity. Cookies are mainly used to make the web site more user-friendly, effective and secure. We use the following cookies on our web site:

Necessary Cookies:

Cookie Name:    sid
Purpose:    Recognizes your visit on our site and that you have visited specific web pages
Expires:    1 Hour
Sample content:    9121628031b03348675514f62a66

Cookie Name:    cookies-accepted
Purpose:    This cookie is used to record whether the cookie information bar has been viewed and whether the setting of certain cookie categories has been accepted.
Expires:    1 Year
Sample content:    ["default","analysis"]

The data processed by necessary cookies are required for the purposes of providing website functionality in order to protect our legitimate interests which result thereof, as well as those of third parties according to Art. 6 para. 1 lit. f GDPR.


Cookies for advertising and marketing:

Cookie Name:    _ga
Provider:    Google
Purpose:    Google Universal Analytics. Differentiation of unique users by randomly generated number as client ID. Used to identify returning visitors, calculate visitor, session and campaign data.
Expires:    2 Year
Sample content:    GA1.3.1369932704.1580458261
Further Information:    https://policies.google.com/privacy?hl=en

Cookie Name:    _gat
Provider:    Google
Zweck:    Google Aanlytics: throttles the request rate to limit data collection on high traffic websites
Expires:    10 Minutes
Sample content:    1
Further Information:    https://policies.google.com/privacy?hl=en

Cookie Name:    _gid
Provider:    Google
Purpose:    Google Universal Analytics. Used to distinguish users.
Expires:    24 Hours
Sample content:    GA1.3.1183256634.1586250684
Further Information:    https://developers.google.com/analytics/devguides/collection/analyticsjs/cookie-usage?hl=en

Most browsers accept cookies automatically. However, if you do not wish to accept cookies, you can configure your browser so that no cookies are stored on your device or a message is displayed before new cookies are created. Information on how to remove cookies in Internet Explorer / Edge, please refer to: https://support.microsoft.com/en-gb/help/17442/windows-internet-explorer-delete-manage-cookies. Information on the removal of cookies in Firefox, please refer to: https://support.mozilla.org/en-US/kb/clear-cookies-and-site-data-firefox?redirectlocale=en-US&redirectslug=delete-cookies-remove-info-websites-stored. Learn how to remove cookies in Safari here: https://support.apple.com/en-gb/guide/safari/sfri11471/mac.
A general objection to the use of cookies used for online marketing purposes can be made for a variety of services, such as explained at http://www.youronlinechoices.com/or the opt-out page of the Network Advertising Initiative https://optout.networkadvertising.org. However, disabling cookies may mean that you may not be able to use all the features of our web site.

III. Individual processing operations

1.    Hosting
In order to make available our web site, we use services provided by hosting companies, such as: Provision of web servers, disk space, database services, and security or maintenance services. Here we, or our hosting providers, process personal data of the web site visitors on the basis of our legitimate interests in providing efficient and secure access to our web site in accordance with Art. 6 para. 1 lit. f GDPR.

2.    Access data and log files
By visiting our web site or its individual pages, your device’s internet browsers automatically sends information to the server of our web site. This information is stored in so-called log files by us or our hosting provider and will be deleted after 4 days at the latest.

The following information is stored:
    
-    IP address of the requesting computer;
-    Date and time of access;
-    Name and URL of the requested file;
-    Web site from which our site was accessed (Referrer-URL);
-    The browser used and your computer’s operating system;
-    Status codes and the transferred amount of data;
-    Name of your access providers.

This data will be used for the following purposes:

-    The provision of our web site, including all of its features and contents;
-    To ensure a smooth connection to our web site;
-    To ensure the comfortable use of our web site;
-    To ensure system security and stability;
-    For anonymised statistical evaluation of web site access;
-    For disclosure to law enforcement authorities in the event of unlawful interference / attacks on our systems;
-    For further administrative purposes.

The legal basis for data processing is Art. 6 para. 1 lit. f GDPR. Our legitimate interest follows from the data collection purposes mentioned above. Under no circumstance will we use the personal data collected for the purpose of drawing conclusions about a person.

3.    General means of contact
If you contact us using the contact details published in our web site (for example, by e-mail) and in this context provide us with personal data, we will use this data to process your request on the basis of Art. 6 para. 1 lit. b GDPR, if your request is related to the performance of a contract or is required to perform pre-contractual action. In all other cases, processing is based on your consent in accordance with Art. 6 para. 1 lit. a GDPR and / or our legitimate interest in the effective processing of requests addressed to us pursuant to Art. 6 para. 1 lit. f GDPR. We will store your personal data until you ask us for deletion, revoke your consent to the storage, or the data are no longer necessary for the purpose for which they were collected (for example, after completion of your request). Mandatory statutory provisions - especially retention periods - remain thereof unaffected.

4.    Job application
If you wish to apply for a job, please provide us with your name, contact information and further application documents so that we can review your application and get in personal contact with you. The data processing for the purpose of processing your application is carried out in accordance with Art. 6 para. 1 lit. a GDPR based on your voluntary consent. Taking into account the limitation periods of the General Equal Treatment Act (AGG), application documents will be kept for a period of 6 months after completion of the application process and then deleted, unless storage is required for the documentation of other operations (for example, subsequent recruitment).

IV. Google Services

Provider of the services below is Google Ireland Limited (Register No: 368047), Gordon House, Barrow Street, Dublin 4, Ireland (hereinafter 'Google').
The information collected by Google in connection with the provision of the respective services may be transferred to and processed by Google servers in the USA. Google entered into Standard Contractual Clauses to comply with the requirements of the GDPR to legitimately transfer personal data in third countries outside the European Union (EU) or the European Economic Area (EEA). A copy of the EU Standard Contractual Clauses can be found at: https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32010D0087&from=en. Please also note our information on data transfer to third countries, see above.
For more information about how Google handles personal data, please refer to Google's Privacy Policy: https://www.google.com/intl/de/policies/privacy. For information on the use of data for advertising purposes by Google, settings and your right to object please refer to: https://www.google.de/policies/privacy/partners, https://www.google.de/policies/technologies/ads, https://adssettings.google.de
1. Google services for which your consent is required
The legal basis for the use of the following services is your voluntarily given consent according to Art. 6 (1)(a) GDPR. The legal basis for data transfer to the USA is also your voluntarily given consent in accordance with Art. 49 (1)(a) GDPR.
1.1 Google Analytics
Our website uses Google Analytics. Google Analytics uses cookies. Google Analytics collects information about the visits of website users and analyses their behaviour. This data serves the purpose of developing a user-friendly website design, the continuous optimisation of our services and offers, to measure the success of marketing activities and to create statistical analysis. In this context, pseudonymised user profiles are created and cookies are used. Google Analytics collects information such as browser type / version, operating system, referrer URL (the previously visited page), host name of the accessing computer (IP address) and time of server request. The information generated is transferred to the US and stored on servers owned by Google. The collected user data and event data will be deleted after 26 months. Information may also be transferred to third parties if required by law or if third parties process this data on behalf of us or Google. Under no circumstances will your IP address be merged with any other data that is kept by Google. The IP address will be anonymised so that assignment is impossible. You can prevent the local storage of cookies by configuring your browser software accordingly. However, be advised that in this case you may not be able to use all the features of this website to the full extent possible. Additionally, in order to prevent Google from collecting and processing the data generated in relation to your use of the website you may download and install the browser plug-in available under the following link: https://tools.google.com/dlpage/gaoptout?hl=en. You can prevent Google from gathering your data by clicking on this link [<a href='javascript:gaOptout()'>Deactivate Google Analytics</a>] which sets an opt-out cookie on your computer. This cookie ensures that Google Analytics will not collect and store any user data from your browser when visiting this website. Attention: If you delete your cookie cache, this will result in the opt-out cookie being deleted as well. Then you must re-activate the opt-out cookie again.

V. Use of SalesViewer® technology

Use of SalesViewer® technology:
This website uses SalesViewer® technology from SalesViewer® GmbH on the basis of the website operator’s legitimate interests (Section 6 paragraph 1 lit.f GDPR) in order to collect and save data on marketing, market research and optimisation purposes.
In order to do this, a javascript based code, which serves to capture company-related data and according website usage. The data captured using this technology are encrypted in a non-retrievable one-way function (so-called hashing). The data is immediately pseudonymised and is not used to identify website visitors personally
The data stored by Salesviewer will be deleted as soon as they are no longer required for their intended purpose and there are no legal obligations to retain them.
The data recording and storage can be repealed at any time with immediate effect for the future, by clicking on https://www.salesviewer.com/opt-out in order to prevent SalesViewer® from recording your data. In this case, an opt-out cookie for this website is saved on your device. If you delete the cookies in the browser, you will need to click on this link again.

VI. Media content

In the context of providing our web site we partially use third party content, which is loaded directly from servers of the content providers, as named below. The purpose of integrating this content is to make our web site more attractive. The legal basis is our legitimate interest pursuant to Art. 6 para. 1 lit. f GDPR in using such external content to make our web site more attractive.

Bing maps
This website uses Bing Maps to display site plans, map material, terrain data or geographical maps. The provider is Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399 USA (hereinafter 'Microsoft'). This service records your IP address, which of our Internet pages you have visited and, if applicable, further data required by Microsoft for the provision of the maps (e.g. location data). The information generated is stored on a server in the USA. This information may also be transferred to third parties if this is required by law or if third parties process this data on behalf of us or Microsoft. The terms and conditions for the use of Bing Maps can be found at: https://www.microsoft.com/maps/assets/docs/terms.aspx.