Privacy policy

The following data protection notices inform you how GBA Holding GmbH and its subsidiaries handle your data. We inform you about the collection, storage and use of personal data, the legal basis for processing and your rights with respect to us.

We have taken technical and organizational measures to ensure that data protection regulations are observed both by us and by our technical partners and service providers.

On our homepage, only the personal and business data necessary for our service offer are recorded. All other information is voluntary. Furthermore, we assure you that we will not pass on your data stored with us to third parties or use it for any other purpose, e.g. for advertising by third parties, without your consent.

The following statements apply to all anonymous and registered, logged in users who have read-only access. Only a few specific GBA Group employees have write access. Other internal rules apply to them.

We attach great importance to the sensitive handling of all data provided by you and assure you of comprehensive data protection.

With regard to the definition of terms such as "personal data" or "processing" we refer to Article 4 GDPR.

1. Name and contact details of the person responsible

Those responsible for the website in accordance with Article 4 paragraph 7 of the EU Data Protection Regulation (GDPR) are

GBA Holding GmbH
Goldtschmidtstraße 5
21073 Hamburg,

represented by the CEO Steffen Walter.

This data protection information also extends to our Group companies. Each Group company is a responsible party in the sense of data protection law.

The names and contact persons of the responsible data protection officers can be found here.

You can contact the data protection officer of GBA Holding GmbH at
datenschutz@gba-group.de.

2. Provision of the website and log files

Description and scope of the data processing

Whenever our website is called up, our system, i.e. the web server, automatically records information from the calling computer or end device of the user. If you only use our website for information purposes (i.e. no registration or other transmission of information), we only collect the personal data that your browser sends to our server. We collect the following data:

  • information about the browser type and version used
  • the operating system of the user's end device
  • the Internet service provider of the user
  • the IP address of the user
  • date and time of access
  • form data

This data will not be stored together with other personal data of yours. The data serves the purpose of user-friendly, functional and secure delivery of our website to you with functions and contents as well as their optimization and statistical evaluation.

The legal basis for the temporary storage of this data and the log files is Article 6 paragraph 1 (f) GDPR (our legitimate interests as a responsible website operator).

Purpose of the data processing

The temporary storage of the user's IP address by our system is necessary to enable the website to be delivered to the user's computer. For this purpose, the user's IP address must necessarily remain stored for the duration of the session.

The storage of the above-mentioned data in the log files is done to ensure the functionality of our website. In addition, this data serves us to optimize the website and to ensure the security of our information technology systems (e.g. to detect attacks). An evaluation of the data for marketing purposes does not take place in this context.

Duration of storage

To ensure the error-free functionality of our website, we store this data in server log files for a period of 190 days for security reasons. After this period has elapsed, they are automatically deleted, unless we need to keep them for evidence in case of attacks on the server infrastructure or other legal violations.

Normally there is no access to these log files, but if errors occur, they are used to investigate the cause.

3. Cookies

Description and scope of the data processing

We use so-called cookies when you visit our website. Cookies are small text files that your internet browser places and stores on your computer. When you visit our website again, these cookies provide information to automatically recognize you.

Our website uses session cookies, persistent cookies and third- party cookies:

Session cookies: We use so-called cookies to recognize multiple use of an offer by the same user (e.g. if you have logged in to determine your login status). When you visit our site again, these cookies provide information to recognize you automatically. The information obtained in this way serves to optimize our offers and to make it easier for you to access our site. When you close the browser or log out, the session cookies are deleted.

Persistent cookies: These are automatically deleted after a predetermined period of time which may vary depending on the cookie. You can delete or block the cookies at any time in the security settings of your browser.

Third-party cookies: You can configure your browser settings according to your wishes and, for example, refuse to accept third- party cookies or all cookies. However, we would like to point out at this point that you may then not be able to use all functions of this website. Please read more about these cookies in the respective privacy statements of the third-party providers we use.

The legal basis for the processing is our legitimate interest (Article 6 paragraph 1 (f) GDPR) for essential cookies or your - at any time revocable - consent pursuant to Article 6 paragraph 1 (a) GDPR.

Purpose of the data processing

The information obtained in this way serves the purpose of optimizing our web offers technically and economically and enabling you to access our website more easily and securely. When you visit our website, you have the option of actively agreeing to the use of cookies for statistical and marketing purposes. Technically necessary cookies ("essential cookies") are needed to provide the functionalities of our website.

Duration of storage

he cookies are stored for different lengths of time. For more information, see the privacy settings in the cookie configuration panel.

General information on cookies

You can generally prevent cookies from being stored on your hard disk by selecting "do not accept cookies" in your browser settings. However, this can result in a functional limitation of our offers. You can object to the use of third-party cookies for advertising purposes by opting out using this American website (https://optout.aboutads.info)
or this European website (http://www.youronlinechoices.com/de/praferenzmanagement/)

4. Contact by e-mail or contact form

Description and scope of the data processing

When you contact us by e-mail or via a contact form, the data you provide (your e-mail address, your name and telephone number if applicable) will be stored by us in order to answer your questions.

On our homepage you have the possibility to fill out our online application form and send it to us. We assure you that we will use the personal data you entrust us with when filling out the application form exclusively in connection with your application. Your data will not be passed on to third parties.

Data on applicants who apply to the GBA Group for an advertised position will be stored in our systems for six months after completion of the vacancy and then deleted. Data of candidates who submit unsolicited applications will be checked and deleted if no suitable vacancy exists. If there is a suitable position available, this data will be used within the application process, especially for making contact. No applicant data will be passed on to third parties or transferred to a third country. You will find further information on this in our data protection.

The legal basis for the processing of these data, which are transmitted in the course of a request, is Article 6 paragraph 1 (f) GDPR (our legitimate interests as the responsible party). In this case, our legitimate interest is a commercial interest, such as answering your enquiry, acquiring customers or similar.

If necessary, Article 6 paragraph 1 (b) GDPR (fulfilment of contract) can be an additional legal basis for the processing, as we can only come back to you and your request if we know a way to contact you. We use these data exclusively to be able to get back to you regarding the communicated concern.

Purpose of the data processing

The processing of this personal data serves us solely to process the contact.

Duration of storage

The above-mentioned data will be deleted as soon as they are no longer necessary for the purpose of their collection. For personal data sent by e-mail or contact form, this is the case when the respective conversation with the user has ended. The conversation is terminated when it can be concluded from the circumstances that the matter in question has been finally clarified.

Right of objection

The user has the possibility at any time to object to data processing based on our legitimate interest. The objection is to be sent to the following e-mail address:

datenschutz@gba-group.de.

In this case, all personal data stored in the course of the contact will be deleted, unless this is contrary to statutory storage obligations. For further information, please refer to the section on the rights of data subjects and the note on the right of objection (point 9).

5.Search function on the website

Description and scope of data processing

We use the search function of the provider Algolia Inc. on our website to search for and index content. By using Algolia, your IP address and your search query are transmitted to Algolia's servers and stored there for 90 days for statistical purposes. Please note the terms of use of Algolia and the privacy policy of the provider.

The legal basis for the processing of these data, which are transmitted in the course of a request, is Article 6 paragraph 1 (f) GDPR (our legitimate interests as the responsible party). In this case, our legitimate interest is a presentable and user-friendly usability of our website.

Purpose of the data processing

The use of Algolia is for the purpose of making the information contained on our website easier to find and thus ensuring user- friendliness.

Duration of storage

The data is stored on the server of Algolia for a period of 90 days.

Right of objection

The user has the possibility at any time to object to data processing based on our legitimate interest. The objection should be sent to the following e-mail address:

datenschutz@gba-group.de

In this case, all personal data stored in the course of the contact will be deleted, unless this is contrary to statutory storage obligations. For further information, please refer to the section on the rights of data subjects and the note on the right of objection (point 9).

13. Recipients/categories of recipients

Recipients of your data are regularly employees of our company who are entrusted with the processing of inquiries and contracts. In addition, we use contractually bound data processors and partners for various services who sometimes act as independent responsible persons.

Without your consent we do not pass on any data to third parties. Should this be the case, however, the transfer will take place on the basis of the aforementioned legal bases or due to a court order or due to a legal obligation to hand over the data for the purpose of criminal prosecution, danger prevention or to enforce intellectual property rights. The data will not be passed on for other non- commercial or commercial purposes

We use contract processors (external service providers e.g. for web hosting of our websites and databases) to process your data. If data is passed on to the processors within the framework of an agreement on order processing, this is always done in accordance with Article 28 GDPR. We select our processors carefully, check them regularly and have the right to give instructions regarding personal data. In addition, the processors must have taken suitable technical and organizational measures and comply with the data protection regulations in accordance with the Federal Data Protection Act and GDPR. Processors are not considered third parties as defined in Article 4 No. 10.

14. Transfer of data to third countries

Should the processing be carried out by services of third parties outside the European Union or the European Economic Area, they must comply with the specific conditions of Article 44 et seq. GDPR. This means that the processing is carried out on the basis of specific guarantees, such as the EU Commission's officially recognized determination of a level of data protection equivalent to that of the EU or the observance of officially recognized specific contractual obligations, the so-called "standard contractual clauses". For US companies, submission to the so-called "privacy shield", the data protection agreement between the EU and the USA, fulfils these requirements.

Without appropriate data protection guarantees, a transfer of your data to a third country is not permitted.

15. The need to provide personal data

The necessity to provide personal data results from the use of our website or our services and depends on the respective degree of use and the requested services.

If you have any questions, please send us an e-mail to datenschutz@gba-group.de.

16. Existence of automated decision-making

We do not use automated decision making or profiling.

17. Data security

In order to protect all personal data transmitted to us and to ensure that the data protection regulations are observed by us and our external service providers, we have taken appropriate technical and organizational security measures. For this reason, all data between your browser and our server is transmitted encrypted via a secure SSL connection.

Our internet offer may contain links to websites of other providers. We have no influence on whether these providers adhere to the data protection regulations.

© 2024 GBA Group

    Privacy policyDisclosureLegal Notice