Preamble
This text explains what types of personal data concerning you (also referred to herein as “data”) Dussmann processes for which purposes and in what scope. This Data Protection and Privacy Statement applies to all processing of personal data by Dussmann, both within the context of the use of the Dussmann online career portal and on Dussmann websites (collectively referred to as “online services”) or in the case of applications received by e-mail or submitted on site.
It is important to note that Dussmann is not merely a single company. It is a group of companies consisting of Dussmann Stiftung & Co. KGaA and its affiliates. A list of these affiliates can be viewed here. Not every one of these affiliates does in fact process your data. For ease of reference, the “Controller” section notes which company is responsible for processing your data. This means that where the text below refers to “us” or “we”, this means the responsible company of the Dussmann Group that is mentioned in the “Controller” section.
Please check back regularly to familiarize yourself with the content of our Data Protection and Privacy Statement. We adjust the text promptly as required by changes in the data processing we perform. We will let you know if and when these changes require any participatory action on your part (such as consent) or another form of individual notification is necessary.
Where we state the addresses and contact information of companies and organizations in this Data Protection and Privacy Statement, please note that these addresses may change over time and should be verified before you contact us.
Controller
Dussmann Stiftung & Co. KGaA
Friedrichstrasse 90
10117 Berlin
Germany
e-mail address: hotline @dussmanngroup.com
Phone: +49 30 20 250
Data protection officer contact
Dussmann Stiftung & Co. KGaA
Data Protection Officer
Friedrichstrasse 90
10117 Berlin
Germany
+49 30 20250
datenschutz
@dussmanngroup.com
Overview of processing
The overview below summarizes the types of data we process and the purposes of processing thereof and indicates the data subjects.
Types of data processed
Special categories of data
Categories of data subjects
Purposes of processing
Relevant legal bases
Relevant legal bases pursuant to the GDPR: This section provides an overview of the legal bases under the GDPR on which we process personal data. Please note that in addition to the provisions of the GDPR, national data protection and privacy specifications may apply in your or our country of residence or domicile. Should more-specific legal bases be relevant in the individual case, we will notify you of these in the Data Protection and Privacy Statement.
National data protection regulations in Germany: In addition to the data protection regulations stipulated by the GDPR, there are national regulations governing data protection and privacy in Germany. This particularly includes German Federal Data Protection Act (BDSG). In particular, the BDSG contains special provisions relating to the rights of access to information, of erasure, and to object; the processing of special categories of personal data; processing for other purposes; transfers; and automated decision-making in individual cases, including profiling. Furthermore, state data protection laws at the level of the individual states may also apply.
Security measures
In accordance with the legal specifications and taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, we implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk.
These measures include but are not limited to ensuring the confidentiality, integrity, and availability of data by controlling physical and electronic access to the data and the data access concerning them, along with the entry, communication, and separation thereof and ensuring the availability of the data. We have also established procedures that ensure that the rights of data subjects are upheld, data are erased, and there is a response to any risk to the data. Furthermore, we take protecting personal data into account in the early stages of developing and/or selecting hardware, software, and procedures in keeping with the principle of data protection by design and by default.
Safeguarding online connections through TLS/SSL encryption technology (HTTPS): To protect the user data transferred via our online services against unauthorized access, we rely on TLS/SSL encryption technology. Secure Sockets Layer (SSL) and Transport Layer Security (TLS) are the cornerstones of secure data transmission on the Internet. These technologies encrypt the information transferred between the website or app and the user’s browser (or between two servers), which protects the data against unauthorized access. TLS, a further developed and more-secure version of SSL, ensures that all data transmissions meet the very highest standards of security. If a website is safeguarded by an SSL/TLS certificate, “HTTPS” is displayed in the URL. This serves as an indicator for users that their data are being transferred securely and with encryption.
Transfers of personal data
Within the scope of our processing of personal data, it is possible that these data will be transferred or disclosed to other bodies, companies, legally independent organizational units, persons, or entities. Recipients of these data may include, for example, service providers commissioned to perform IT tasks or providers of services and content incorporated into a website. In such cases, we observe the legal specifications and, in particular, enter into relevant contracts and/or agreements that serve to protect your data with the recipients of your data.
Data transfers within the corporate group: We may transfer personal data to other companies within our corporate group or grant them access to these data. Where such disclosures take place for administrative purposes, the disclosure of the data is based on our legitimate entrepreneurial and business administration interests or takes place to the extent necessary to fulfill our contract-related obligations or where the data subject has given consent or the disclosure is permitted by law.
International data transfers
Data processing in third countries: Where we process data in a third country (i.e., outside the European Union (EU) or European Economic Area (EEA)) or the processing takes place within the scope of our utilization of third-party services or of the disclosure or transfer of data to other persons or entities, bodies, or companies, this takes place solely in compliance with the legal specifications. Where the level of data protection in the third country has been acknowledged by an adequacy decision (Article 45 GDPR), this decision serves as the basis for the data transfer. In all other respects, data transfers take place only if the level of data protection has been safeguarded through other means, particularly standard contractual clauses (point (c) of Article 46(2) GDPR), express consent has been granted, or the transfer is required based on the provisions of a contract or by law (Article 49(1) GDPR). In all other respects, we communicate to you the bases for the third-country transfer in the case of the individual third-country providers; the adequacy decisions take precedence as bases. For information on third-country transfers and existing adequacy decisions, please consult the information provided by the European Commission: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection_en.
Transatlantic EU–U.S. data privacy framework: Within the scope of the Data Privacy Framework (DPF), the European Commission acknowledged the level of data protection provided by certain companies based in the United States as secure under the adequacy decision dated July 10, 2023. The list of certified companies and further information relating to the DPF is available from the U.S. Department of Commerce website at https://www.dataprivacyframework.gov/.
Information on data storage and erasure
We erase personal data that we process in accordance with the statutory provisions once the underlying consent has been withdrawn or there are no further legal bases for the processing thereof. This applies to cases in which the original purpose of processing ceases to apply or the data are no longer required. Exceptions to this provision apply if statutory obligations or particular interests require that the data be retained or archived for a longer period.
In particular, data that must be retained for reasons of commercial or tax law or whose storage is necessary in order to pursue legal claims or protect the rights of other natural persons or legal entities must be archived accordingly.
We process data that are no longer retained for the originally intended purpose, but rather based on legal specifications or other reasons, exclusively on the bases that justify the retention thereof.
Should you wish your data to be erased or withdraw consent to data processing, the data will be erased as soon as possible unless there is an obligation to store them.
If we are unable to consider your application, your data will be deleted after 6 months at the latest, unless you allow us to store your data in the applicant pool for a longer period in accordance with point (a) of Article 6(1) GDPR. If you withdraw your application, we will of course delete your data immediately. If your application results in the conclusion of a contract with us, your data will be used for the purpose of the organizational and administrative procedure and in compliance with legal regulations.
Further information on processing operations, procedures, and services:
Rights of data subjects
Rights of data subjects under the GDPR: As a data subject, you have various rights under the GDPR, particularly based on Articles 15 through 21 GDPR:
Provision of online services and Web hosting (log files)
We process user data to be able to provide them with our online services. To this end, we process the user’s IP address, which is necessary in order to transfer the content and features of our online services to the user’s browser or device.
Further information on processing operations, procedures, and services:
Use of cookies
Cookies are small text files or other storage notes that store information on devices and read it out from there. This is done, for example, to store the log-in status for a user account, the contents of a shopping cart in an online store, or the content retrieved or features of an online service that are used. Cookies can also be used in relation to various matters, such as for purposes of the functionality, security, and convenience of online services and to prepare analyses of user streams.
Information on consent: We use cookies in accordance with the legal provisions. Therefore, we obtain advance consent from users except where consent is not required by law. In particular, permission is not necessary if storing and reading out the information, including through the use of cookies, is strictly necessary in order to provide users with a tele-media service (meaning our online services) that they have expressly requested. The fact that they are giving consent and that it can be withdrawn is communicated clearly to them in a form that includes the information on the relevant cookie usage.
Information on legal bases for purposes of data protection and privacy law: The legal basis for purposes of data protection and privacy law on which we process users’ personal data using cookies depends on whether we ask users for consent. If users accept, the legal basis for the use of their data is their stated consent. Otherwise, the data used via cookies are processed on the basis of our legitimate interests (e.g., in the cost-effective operation of our online services and improvement of the usability thereof) or, if this takes place within the scope of fulfillment of our contractual obligations, if the use of cookies is necessary in order to comply with our contractual obligations. We provide information on the purposes for which we use cookies elsewhere in this Data Protection and Privacy Statement or within the scope of our consent and processing procedures.
Duration of storage: With regard to the duration of storage, a distinction is made between the following types of cookies:
General information on withdrawal of consent and objections (opting out): Users can withdraw the consent they have given at any time and can also object to the processing of their data in accordance with the legal specifications, including using their browser’s privacy settings.
Further information on processing operations, procedures, and services:
Contact and inquiry management in the course of the application
When people contact us in the course of an application (e.g., by career portal, email, phone, or via social media) ), the data of the applicant will be processed to the extent necessary to carry out the application process. We collect different types of information. This includes in particular your personal data with contact information as well as a description of your education, work experience and skills. In addition, you have the option of providing us with electronically stored documents such as certificates or cover letters. Please note that CVs, references or other data you send us for the purposes of your application may also contain particularly sensitive data (Article 9 GDPR). We therefore recommend that you do not provide any information relating to particularly sensitive data (e.g. information on mental and physical health, racial or ethnic origin, political opinions, religious or philosophical beliefs, membership of a trade union or political party). If you provide us with this type of information, you expressly agree that we may process this data for the purpose of carrying out the application process. This data will be processed in accordance with this privacy policy and other relevant legislation.
Further information on processing operations, procedures, and services:
Contact and inquiry management in the course of the application of minors
If you are still a minor, i.e. have not yet reached the age of 18, and would like to apply to us, we require that you have the consent of your legal representatives (usually your parents). If you have not yet reached the age of 16, your application must be accompanied by a declaration of consent from your legal representatives. If we do not have this declaration of consent, your application cannot be considered and your data will be deleted immediately.
Videoconferences, online meetings, webinars, and screen sharing
We use platforms and applications from other providers (collectively “conference platforms”) for purposes of holding video and audio conferences, webinars, and other types of video and audio meetings (collectively “conferences”). We observe the legal specifications in selecting conference platforms and their services.
Data processed by conference platforms: In the context of participation in a conference, the conference platforms process the personal data of participants as mentioned below. The scope of the processing depends on factors including which data are specifically required in the context of a concrete conference (e.g., provision of login information or real names) and which optional information is provided by participants. In addition to processing to hold the conference, the participants’ data may also be processed by the conference platforms for security purposes or to optimize services. The data processed include personal information (first name, last name), contact information (e-mail address, phone number), login information (login codes or passwords), profile pictures, information about the person’s professional position/title or role, the IP address of the Internet access, information on participants’ devices, operating system, browser, and technical and language settings, information on content-related communication procedures, i.e., entries in chats and audio and video data, along with the use of other available features (such as surveys or polls). The content of the communications is encrypted to the extent provided in technical terms by the conference providers. If the participants are registered with the conference platforms as users, then additional data may be processed as agreed with the relevant conference provider.
Logging and recordings: If text entries, results of participation (e.g., in surveys or polls) and video or audio recordings are logged, this is communicated transparently to the participants in advance, and they are asked to consent where necessary.
Data protection measures of participants: With regard to the details of the processing of your data by the conference platforms, please note the latter’s data protection and privacy information and select the security and data protection and privacy settings that are optimal for you within the scope of the conference platform settings. Furthermore, please ensure data protection and privacy in the background of your images or recordings for the duration of a videoconference (e.g., by notifying others with whom you live, closing doors, and using any available technical features to blur your background). Links to conference rooms and login information must not be disclosed to unauthorized third parties.
Information on legal bases: Where we also process users’ data in addition to the conference platforms and request consent from users to the use of the conference platforms or certain features (e.g., consent to the recording of conferences), the legal basis of processing is this consent. Furthermore, our processing may be necessary in order to fulfill our contractual obligations (e.g., in participant lists, in the case of processing of the results of discussions or meetings, etc.). In all other respects, user data are processed on the basis of our legitimate interests in efficient and secure communication with the other parties to communications with us.
Further information on processing operations, procedures, and services:
Web analysis, monitoring, and optimization
Web analysis (also known as “reach measurement”) serves to analyze the visitor streams to our online services and may encompass behavior, interests, or demographic information on visitors, such as age or gender, as pseudonymized values. We can use reach analysis to see, for example, the time at which our online services or their features or content are used most frequently or to invite people to use them again. It is also possible for us to track which areas require optimization.
In addition to Web analysis, we may also use test methods to test and optimize aspects such as different versions of our online services or their components.
Unless otherwise indicated below, profiles, meaning data compiled on a use operation, may be created for these purposes, and information may be stored in a browser or on a device and then retrieved. The information collected includes but is not limited to websites visited and elements used there, along with technical information such as the browser and computer system used and information on usage times. Where users have consented, either to us or the providers of the services used by us, to the collection of their location data, processing of location data is also possible.
Beyond that, users’ IP addresses are stored. However, we use an IP masking procedure (i.e., pseudonymization by truncating (shortening) the IP address) to protect users. In general, no real information pertaining to users (such as e-mail addresses or names) is stored in the context of Web analysis, A/B testing and optimization. Instead, this information is pseudonymized. This means that neither we nor the providers of the software used know the actual identity of the user. Instead, all that is known is the information stored in the users’ profiles for the purpose of the relevant operations.
Information on legal bases: Where we ask users for their consent to the use of third parties, the legal basis for data processing is consent. Otherwise, user data are processed on the basis of our legitimate interests (i.e., interest in efficient, cost-effective and user-friendly services). In this context, we would also like to point out the information on the use of cookies in this Data Protection and Privacy Statement.
Further information on processing operations, procedures, and services:
Plugins and embedded functions and content
Our online services incorporate functional and content elements obtained from the servers of their respective providers (“third-party providers”). These may include but are not limited to graphics, videos, and maps (collectively “content”).
Incorporation of these elements always presupposes that the third-party providers of this content process the IP addresses of users, as without these IP addresses, they would be unable to transmit the content to the users’ browsers. This means the IP address is required in order to present this content or these functions. We strive to use only content whose respective provider uses the IP address solely to deliver the content. Third-party providers may moreover use what are known as pixel tags (invisible graphics also known as Web beacons) for statistical or marketing purposes. These pixel tags allow for analysis of information such as user traffic to the pages of this website. This pseudonymized information can furthermore be stored in cookies on the user’s device and may include items such as technical information on the browser and operating system, referring websites, the time of the visit, and further information on the use of our online services. It may also be associated with such information from other sources.
Information on legal bases: Where we ask users for their consent to the use of third parties, the legal basis for data processing is permission. Otherwise, user data are processed on the basis of our legitimate interests (i.e., interest in efficient, cost-effective and user-friendly services). In this context, we would also like to point out the information on the use of cookies in this Data Protection and Privacy Statement.
Further information on processing operations, procedures, and services:
Google Maps: We incorporate maps from the Google Maps service provided by Google. The data processed may include but are not limited to users’ IP addresses and location information; service provider: Google Cloud EMEA Limited, 70 Sir John Rogerson’s Quay, Dublin 2, Ireland; legal bases: consent (point (a) of Article 6(1) GDPR); website: https://mapsplatform.google.com/; privacy policy: https://policies.google.com/privacy. Basis for third-country transfers: Data Privacy Framework (DPF).