Below you will find out how we, as the data controller under data protection law, process your personal data when you visit our website and what your rights are in this regard.
Personal data is all data that can be related to you personally, e.g. name, address, email addresses, IP addresses and also your user behaviour on our website.
When processing your data, we comply with the provisions of the European General Data Protection Regulation (“GDPR”) and the German Federal Data Protection Act (“BDSG”).
Contact details of the person responsible:
HRpepper GmbH & Co. KGaA (hereinafter referred to as “HRpepper”)
Tempelhofer Ufer 11
10963 Berlin
Phone: +49 30 2593575 0
E-mail: info@hrpepper.de
Contact details of the data protection officer:
Christoph Heinrich
Stresemannstr. 29
22769 Hamburg
www.ddsc.de
E-mail address: datenschutzkoordinator@hrpepper.de
A. How is my data processed and for what purposes?
1. Protocol data
When you visit our website, the following log data is processed:
- Your IP address
- the operating system you are using
- the web browser you are using
- the screen resolution you have set
Temporary storage of the IP address is necessary to enable the retrieved data to be delivered to the user’s electronic device. For this purpose, it is necessary for the user’s IP address to be stored for the duration of the session. Other data is stored in log files to ensure the functionality of the website.
The storage period is 14 months. The data is deleted when it is no longer required to fulfil the purposes for which it was collected. This data is processed on the basis of Art. 6 para. 1 lit. f GDPR. Our legitimate interest lies in achieving the purposes described above.
2. Cookies
In addition to the aforementioned data, cookies are stored on your computer when you use our website. Cookies are small text files that are stored on your end device. Cookies cannot execute programmes or transfer viruses to your computer. We use cookies to make our website user- friendly and clear.
The legal basis for data processing is Art. 6 para. 1 lit. f) GDPR, based on our legitimate interest in making our website more user-friendly and effective.
You can configure a browser setting according to your wishes and, for example, refuse to accept third-party cookies or all cookies. We would like to point out that you may not be able to use all functions of this website.
Cookie consent with Borlabs Cookie
Our website uses Borlabs Cookie’s cookie consent technology to obtain your consent to the storage of certain cookies in your browser and to document this in accordance with data protection regulations. The provider of this technology is Borlabs – Benjamin A. Bornschein, Georg- Wilhelm- Str. 17, 21107 Hamburg, Germany (hereinafter referred to as Borlabs).
When you enter our website, a Borlabs cookie is stored in your browser, in which the consents you have given or the revocation of these consents are stored. This data is not passed on to the provider of Borlabs Cookie.
The data collected will be stored until you ask us to delete it or delete the Borlabs cookie yourself or until the purpose for data storage no longer applies. Mandatory statutory retention periods remain unaffected. You can find details on the data processing of Borlabs Cookie at https://de.borlabs.io/kb/welche-daten-speichert-borlabs-cookie/
Borlabs cookie consent technology is used to obtain the legally required consent for the use of cookies. The legal basis for this is Art. 6 para. 1 sentence 1 lit. c GDPR.
Cookie list:
a) Essential
Essential cookies enable basic functions and are necessary for the proper functioning of the website.
Borlabs Cookie
Name | Borlabs Cookie |
---|---|
Provider | Owner of this website, legal notice |
Purpose | Saves the settings of the visitors selected in the Cookie Box of Borlabs Cookie |
Cookie Name | borlabs-cookie |
Cookie runtime | 1 year |
WooCommerce
Name | WooCommerce |
---|---|
Provider | Owner of this website |
Purpose | Helps WooCommerce detect when the content of the shopping cart/data changes. Contains a unique code for each Shopping basket data can be finden in the database for each customer. Enables customers to receive the shop notifications |
Cookie Name | woocommerce_cart_hash, woocommerce_items_in_cart, wp_woocommerce_session_, woocommerce_recently_viewed, store_notice[notice id] |
Cookie runtime | Session / 2 day |
Google Tag Manager
Name | Google Tag Manager |
---|---|
Provider | Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland |
Purpose | Cookie von Google zur Steuerung der erweiterten Script- und Ereignisbehandlung. |
Privacy Policy | https://policies.google.com/privacy?hl=de |
Cookie Name | _ga,_gat,_gid |
Cookie Laufzeit | 2 years |
b) Statistics
Statistics cookies collect information anonymously. This information helps us to understand how our visitors use our website.
Google Analytics
Name | Google Analytics |
---|---|
Provider | Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland |
Purpose | Cookie from Google for website analyses. Generates statistical data on how the visitor uses the website. |
Privacy Policy | https://policies.google.com/privacy?hl=de |
Cookie Name | _ga,_gat,_gid |
Cookie runtime | 2 years |
c) Marketing
Marketing cookies are used by third-party providers or publishers to display personalised advertising. They do this by tracking visitors across websites.
d) External Media
Content from video platforms and social media platforms is blocked by default. If cookies from external media are accepted, access to this content no longer requires manual consent.
3. Web Analysis
We use the web analytics service Google Analytics for the purposes of advertising, market research and analysing website activity. Google Analytics is a service provided by Google Inc (“Google”).
Google Analytics uses so-called “cookies” – text files which are stored on your computer and which enable your use of the website to be analysed.
The following personal data is processed:
- IP address,
- Browser type/version,
- operating system used,
- Referrer URL (the previously visited page),
- Host name of the accessing computer (anonymised IP address),
- Time of the server request.
The data generated by the cookies about your use of our website is usually transferred to a Google server in the USA and stored there. However, this website uses Google Analytics with the extension “_anonymiseIp()”. This means, that IP addresses are further processed in abbreviated form; direct personal identification can thus be ruled out (pseudonymisation).
The truncation is carried out by Google on servers within the European Union or in other signatory states to the Agreement on the European Economic Area (EEA). Only in exceptional cases is the full IP address transmitted to a Google server in the USA and only truncated there. The IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data. We have also concluded an order processing contract with Google LLC (USA) in accordance with Art. 28 GDPR. Google will therefore only use all information strictly for the purpose of analysing the use of our websites for us and compiling reports on website activity.
Your data will only be processed in connection with Google Analytics if you have consented to this (Art. 6 para. 1 lit. a GDPR). You can revoke such consent at any time via the for the future. The following options are available to you for this purpose:
- You inform us that you wish to withdraw your consent.
- You may refuse the use of cookies by selecting the appropriate settings on your browser, however please note that if you do this you may not be able to use the full functionality of this website.
- You can also prevent Google from collecting the data generated by the cookie and relating to your use of our websites (including your IP address) and from processing this data by Google by clicking on the following link (https://tools.google.com/dlpage/gaoptout?hl=de) to download and install the available browser plugin.
The lifetime of the cookies is 14 months.
Further information on data processing, purposes and legal bases of data processing and your rights vis-à-vis the processor can be found here: Google Dublin, Google Ireland Ltd, Gordon House, Barrow Street, Dublin 4, Ireland.
You can find the privacy policy of the third-party provider here: http://www.google.de/intl/de/policies/privacy.
4. Social media
Our website contains icons from social networks. These icons are implemented as external links. When you click on an icon, your user data is transferred to the website of the social media platform.
You can also prevent the collection of data and the processing of data by the social media platforms by downloading and installing the available browser add-on on your device.
5. Contact form
We also process the following data if you send enquiries about using our services directly via our contact form:
- Name
- Address
- E-mail address
- Position
- Company name
The data processing takes place exclusively on the basis of and for processing your enquiry. We process your data for the implementation of pre-contractual and contractual measures that are carried out in response to your enquiry (Art. 6 para. 1 sentence 1 lit. b GDPR). In addition, the processing is based on our legitimate interest in the effective processing of the enquiries addressed to us (Art. 6 para. 1 sentence 1 lit. f GDPR).
We store your data for as long as we need it for the specific processing purpose. The data will not be disclosed to third parties without your express consent, unless we are legally obliged to disclose the data to courts or public authorities.
6. Newsletter
With your consent, you can subscribe to our newsletter, which we use to inform you about our current offers. The advertised goods and services are named in the declaration of consent. We process the following data when you subscribe to our newsletter:
- First name and surname
- Your e-mail address
- Company name
After receiving your confirmation, we will save your name and e-mail address for the purpose of sending you the newsletter.
The legal basis for the processing of the data is Art. 6 para. 1 sentence 1 lit. a GDPR.
If you are no longer interested in the newsletter, you can unsubscribe at any time. Your data will then be deleted from the mailing list immediately. You can cancel your subscription by Click on the link provided in every newsletter e-mail, by e-mail to info@hrpepper.de or by sending a message to the contact details given in the imprint.
7. Use of our webshop
If you wish to place an order in our webshop, it is necessary for the conclusion of the contract that you provide personal data that we need to process your order. Pflichtangaben necessary for the processing of the contracts are marked separately, further information is voluntary.
We process the following data when you place an order in our web shop:
- First name and surname
- Billing address
- Delivery address
- E-mail address
- Telephone number
We process the data you provide to process your order. The legal basis for this is Art. 6 para. 1 sentence 1 lit. b GDPR if you are a private customer and Art. 6 para. 1 lit. f GDPR if you are a corporate customer. In this respect, our legitimate interest lies in the processing of business transactions with companies. Insofar as you also provide the voluntary information and thus consent to this processing, Art. 6 para. 1 sentence 1 lit. a) GDPR is the legal basis for the processing.
The data will not be disclosed to third parties without your express consent, unless we are legally obliged to disclose the data to courts or public authorities.
Due to commercial and tax law requirements, we are obliged to store your address, payment and order data for a maximum period of ten years. However, we restrict processing after two years, i.e. your data will only be used to comply with legal obligations.
To prevent unauthorised access by third parties to your personal data, in particular financial data, the order process is encrypted using SSL/TSL technology.
8. Payment processing
We use PayPal (Europe) S.à r.l. et Cie, S.C.A. (“PayPal”) as an online payment service provider for contract processing. In particular, the following personal data is transmitted to PayPal:
- First name, surname
- address
- IP address
- E-mail address
- Bank details
- data in connection with the order
If you are a private customer, the legal basis for data processing is Art. 6 para. 1 sentence 1 lit. b) GDPR, as the processing of the data is necessary for the payment of the purchase price with PayPal and thus for the execution of the contract, as well as Art. 6 para. 1 sentence 1 lit. f) GDPR, based on our legitimate interest in providing an effective and secure payment option. If you are purchasing for a company, the legal basis for payment processing is Art. 6 para. 1 lit. f GDPR, as we also have a legitimate interest in processing transactions with companies.
PayPal’s terms and conditions and data protection information apply to the payment. You can find PayPal’s privacy policy at: https://www.paypal.com/de/webapps/mpp/ua/privacy-full/.
We also only process this data as long as the processing is necessary for the initiation and, if applicable, fulfilment of the contract with us or we are legally obliged to store it.
9. Transmission to third countries
Data may be transferred to a third country.
10. Applications
When you apply to us, we process data that you provide to us. You can use our web form for this purpose, in which case your data will be transmitted to us in encrypted form. If you send us your application documents by e-mail, the data is not automatically encrypted. We therefore recommend that you use our web form.
We use the information you provide us with to check whether you are suitable for the position. If necessary, applications will be forwarded internally to the people who will decide on filling the vacancy. The next steps will then be agreed. Within the company, only those persons have access to your data who need it for the proper course of our application procedure.
Your data is processed exclusively in data centres in the Federal Republic of Germany.
We process your application data on the basis of Section 26 BDSG, in particular paragraph 1, according to which the processing of data required in connection with the decision on the establishment of an employment relationship is permitted.
Should the data be required for legal prosecution after completion of the application process, data processing may be carried out on the basis of the requirements of Art. 6 GDPR, in particular to safeguard legitimate interests in accordance with Art. 6 para. 1 lit. f) GDPR. Our interest then lies in the assertion or defence of claims. Deletion usually takes place 6 months after the position in question has been filled.
Unfortunately, we may not be able to consider you for the advertised position, but may be happy to come back to you at a later date. In this case, we will ask you whether you agree to your data being stored and checked for consistency with other positions in the company. Your data will then only be used with your consent. We will then keep your data in our applicant pool for a further two years on the basis of Art. 6 Para. 1 lit. a GDPR. Of course, you can let us know at any time if you no longer agree to this.
11. Who uses my data?
Within HRpepper, only those departments have access to your data that need it for the purposes described.
B. What rights do I have?
You have the following rights:
1. Right to information
In accordance with Art. 15 GDPR, you have the right to obtain information about the processing of your personal data.
2. Right to rectification
In accordance with Art. 16 GDPR, you have the right to demand that we correct any incorrect or incomplete personal data concerning you.
3. Right to cancellation
You have the right to request the deletion of your data if the conditions specified in Article 17 GDPR are met. This is the case, for example, if your data is no longer required for the purposes for which it was collected. You can also request deletion of your data if we are processing it based on your consent and you have withdrawn that consent.
4. Right to restriction
You have the right to request the restriction of the processing of your personal data if the requirements of Art. 18 GDPR are met. This is the case, for example, if you dispute the accuracy of your data. You can then request the restriction of processing for the duration of the verification of the accuracy of the data by us.
5. Right to data portability
If the data processing is based on your consent or for the fulfilment of a contract and is also carried out using automated processing, you have the right under Art. 20 GDPR to receive your personal data in a structured, commonly used and machine-readable format and to have it transmitted by us to another data processor.
6. Right of cancellation
In accordance with Art. 7 (3) GDPR, you have the right to withdraw your consent at any time with effect for the future.
7. Objection to data processing
If there are special reasons, you can object to data processing at any time, which is based on a legitimate interest, Art. 21 GDPR.
8. Right to complain
In addition, in accordance with Art. 77 GDPR, you have the right to complain to a supervisory authority about our processing of your data.