
The responsible body within the meaning of the General Data Protection Regulation (GDPR) and other data protection regulations is:
FKN HOLDING GmbH & Co. KG
Kirchensaller Straße 36
74632 Neuenstein/Germany
Telefon +49 7942 106-0
E-Mail: info(at)fkn-group.com
Name and address of the data protection officer
The data protection officer of the data controller is:
Dierk Münch
münch consulting GmbH
Aalbachstr. 48a
97877 Wertheim
Telefon: +49 9397 2543200
E-Mail: datenschutz(at)muench-consulting.de
In accordance with Article 13 GDPR, we will inform you of the legal basis for our data processing. If the legal basis is not specified inthe privacy notice, the following applies: the legal basis for obtaining consent is Articel 6 (1) (a) in conjunction with Article 7 GDPR. Thelegal basis for processing in order to provide our services and fulfil contractual measures, as well as answering inquiries, is Article 6 (1) (b) GDPR. The legal basis for processing in order to fulfil our legal obligations is Article 6 (1) (c) GDPR. If the processing of your data isnecessary to safeguard the legitimate interests of our company or a third party and if your interests, fundamental rights and fundamental freedoms as the data subject do not outweigh the first interest, Article 6 (1) (f) GDPR serves as the legal basis for the processing. In the event that vital interests of the data subject or another natural person require the processing of personal data, Article 6 (1) (d) GDPR serves as the legal basis.
We adhere to the principles of data minimisation in accordance with Article 5 (1) (c) GDPR and storage limitation according to Article 5 (1) (e) GDPR. We only store your personal data for as long as is necessary to achieve the purposes stated here, or as stipulated by the retention periods provided for by law. After the respective purpose no longer applies or after these retention periods have expired,the corresponding data will be deleted as quickly as possible.
This website may contain links to third-party websites or to other websites under our responsibility. If you follow a link to any of thewebsites outside our control, please note that these websites have their own privacy notices. We do not assume any responsibility orliability for these external websites and their privacy notices. Before using these websites, please check whether you agree with their privacy policies.
You can recognise external links either by the fact that they are displayed in a colour which is slightly different from the rest of the textor that they are underlined. Your cursor will show you external links when you move it over such a link. Only when you click on an external link will your personal data be transferred to the destination of the link. The operator of the other website will then receive your IP address, the time at which you clicked on the link, the website you were on when you clicked on the link, and other information that you can find in the respective provider’s privacy notice.
Please also note that individual links may result in data transfer outside the European Economic Area. This could give foreignauthorities access to your data. You may not be entitled to any legal recourse against such data access. If you do not want yourpersonal data to be transferred to the link destination or potentially even accessed by foreign authorities against your will, please do not click on any links.
As a data subject within the meaning of the GDPR, you have the opportunity to assert various rights. The rights of data subjects arising from the GDPR are the right of access (Article 15), the right to rectification (Article 16), the right to erasure (Article 17), the right to restriction of processing (Article 18), the right to object (Article 21), the right to lodge a complaint with a supervisory authority and theright to data portability (Article 20).
Withdrawal:
Some data processing can only be carried out with your explicit consent. You have the option of revoking your consent at any time.However, the lawfulness of the data processing until the revocation is not affected by this.
Right to object:
If the processing is based on Art. 6 (1) (e) or (f) GDPR, you as a data subject can object to the processing of personal data concerningyou at any time for reasons arising from your particular situation. You are also entitled to this right in the case of profiling based onthese provisions within the meaning of Art. 4 (4) GDPR. If we cannot prove a legitimate interest for the processing that outweighs your interests, rights and freedoms or if the processing serves to assert, exercise or defend legal claims, we will refrain from processing your data after an objection has been made.
If the processing of personal data serves the purpose of direct marketing, you also have the right to object at any time. The sameapplies to profiling, which is related to direct advertising. Again, we will no longer process personal data as soon as you object.
Right to lodge a complaint with a supervisory authority:
If you believe that the processing of personal data concerning you infringes the GDPR, you have the right to lodge a complaint with asupervisory authority, in particular in the Member State of your residence, your place of work or the place of the alleged infringement,without prejudice to any other administrative or judicial remedy.
Right to data portability:
If your data is processed automatically on the basis of consent or performance of a contract, you have the right to receive this data in astructured, commonly used and machine-readable format. In addition, you have the right to request the transfer and provision of thedata to another controller, insofar as this is technically feasible.
Right to information, correction and deletion:
You have the right to obtain information about your processed personal data regarding the purpose of the data processing, thecategories, the recipients and the duration of storage. If you have any questions on this topic or on other topics regarding personaldata, you can of course contact us via the contact options given in the imprint.
Right to restriction of processing:
You can assert the restriction of the processing of your personal data at any time. To do this, you must meet one of the followingrequirements:
Restriction of processing means that, apart from storage, the personal data may only be processed with your consent or for the establishment, exercise or defence of legal claims, or for the protection of the rights of another natural or legal person, or for reasonsof important public interest of the Union or of a Member State.
Our website is hosted by:
STRATO GmbH
Otto-Ostrowski-Straße 7, 10249 Berlin
Germany
When you access our website, we automatically collect and store information in so-called server log files. Your browser automaticallytransmits this information to our server or our hosting company’s server.
These are:
This data is not merged with other data sources.
Instead of operating this website on our own server, we may also commission an external service provider (hosting company) to operate it on their own server, which we have named above in this case. The personal data collected by this website will be stored on the hosting company’s servers. In addition to the data mentioned above, the web host also stores for us, for example, contact requests, contact details, names, website access data, meta and communication data, contract data and other data generated via awebsite.
The legal basis for processing this data is Article 6 (1) (f) GDPR. Our legitimate interest is the technically error-free presentation and optimisation of this website. If the website is called up in order to enter into contract negotiations with us or to conclude a contract, thisserves as a further legal basis (Article 6 (1) (b) GDPR). In the event that we have commissioned a hosting company, a order processing contract will have been agreed with this service provider.
Our website uses local storage items, session storage items and/or cookies. Local storage is a mechanism that enables data to bestored within the browser on your end device. This data usually includes user preferences, such as the "day" or "night" mode of awebsite, and is retained until you manually delete the data. Session storage is very similar to Local storage, whereas the storageduration only lasts during the current session, so until the current tab is closed. The session storage objects are then deleted from yourend device. Cookies are information that a web server (server that provides web content) stores on your end device in order to be ableto identify this end device. They are either temporarily deleted for the duration of a session (session cookies) and after your visit to a website or permanently (permanent cookies) on your end device until you delete them yourself or they are automatically deleted by your web browser.
These objects can also be stored on your end device by third-party companies when you visit our site (third-party requests). This allows us, as the operator, and you, as a visitor to this website, to make use of certain third-party services installed on this website. Examples are the processing payment services or displaying videos on a website.
These mechanisms have a variety of uses. They can improve the functionality of a website, control shopping cart functions, increasethe security and comfort of website use and carry out analyses regarding visitor flows and behaviour. Depending on their individualfunctions, they must be classified in terms of data protection legislation. Are they necessary for the operation of the website andintended to provide certain features (shopping cart feature) or serve to optimize the website (e.g. cookies to measure visitorbehaviour), then their use is based on Article 6(1)(f) GDPR. As a website operator, we have a legitimate interest in storing local storageitems, session storage items and cookies in order to ensure the technically error-free and optimized provision of our services. In allother cases, local storage items, session storage items and cookies are only stored with your express consent (Article 6 (1) (a) GDPR).
If local storage items, session storage items and cookies are used by third-party companies or for analysis purposes, we will informyou about this separately in this privacy notice. When required, your consent will be requested and can be revoked at any time.
We use external services on our website. External services are services provided by third parties that are used on our website. This can be done for a variety of reasons, such as embedding videos or website security. When using these services, personal data is alsopassed on to the respective providers of these external services. If we have no legitimate interest in using these services, we will obtain your revocable consent as a visitor to our website before using them (Article 6(1)(a) GDPR).
In order to comply with data protection requirements, we use a consent management tool on our website. This tool enables us toobtain the necessary consents for the setting of cookies or the use of external services. We then store these consents.
The data processing is necessary for compliance with a legal obligation to which the data controller (website operator) is subject.Article 6(1)(c) GDPR is therefore used as the legal basis for the processing.
We use the service on our website Cookiebot. The provider of the service is the Usercentrics A/S, Havnegade 39 1058 Kopenhagen, Denmark.
Further information can be found in the provider's data protection information at the following URL:
https://www.cookiebot.com/de/privacy-policy/.
We use a content delivery network (CDN) to optimise the performance and availability of our website. For this purpose, the service provider who makes this network available will process your IP address and information about when you visited our website. All further information on data processing by this service provider can be found in the company’s privacy notice.
This processing is based on our legitimate interest (Article 6 (1) (f) GDPR).
Our legitimate interest in using a content delivery network is to be able to display our website as quickly, securely and reliably aspossible.
We use the service on our website Bootstrap CDN. The provider of the service is the Volentio JSD Limited, Suite 2a1, Northside House, Mount Pleasant, Barnet, EN4 9EB, Great Britain.
The use of the service may result in data transfer to a third country (USA). The provider is certified according to the EU-U.S. Data Privacy Framework and therefore offers an appropriate level of data protection.
Further information can be found in the provider's data protection information at the following URL:
https://www.jsdelivr.com/terms/privacy-policy
We use the service on our website CloudFlare. The provider of the service is the Cloudflare Germany GmbH, Rosental 7, 80331München, Germany.
The use of the service may result in data transfer to a third country (USA). The provider is certified according to the EU-U.S. Data Privacy Framework and therefore offers an appropriate level of data protection.
Further information can be found in the provider's data protection information at the following URL:
https://www.cloudflare.com/privacypolicy/
We use the service on our website Google APIs CDN. The provider of the service is the Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
The use of the service may result in data transfer to a third country (USA). The provider is certified according to the EU-U.S. Data Privacy Framework and therefore offers an appropriate level of data protection.
Further information can be found in the provider's data protection information at the following URL:
https://business.safety.google/privacy
We use the service on our website Google Static. The provider of the service is the Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
The use of the service may result in data transfer to a third country (USA). The provider is certified according to the EU-U.S. Data Privacy Framework and therefore offers an appropriate level of data protection.
Further information can be found in the provider's data protection information at the following URL:
https://business.safety.google/privacy
We use the service on our website jsDelivr. The provider of the service is the Volentio JSD Limited, Suite 2a1, Northside House, Mount Pleasant, Barnet, EN4 9EB, Great Britain.
The use of the service may result in data transfer to a third country (USA). The provider is certified according to the EU-U.S. DataPrivacy Framework and therefore offers an appropriate level of data protection.
Further information can be found in the provider's data protection information at the following URL:
https://www.jsdelivr.com/terms/privacy-policy
Business processes run faster, more cheaply and with fewer errors if they are automated using software via interfaces. This allows them to be efficiently integrated into the company's processes via its own website or social networks. We use interface software on our website to link different applications and to transfer personal data securely from one application to another.
Processing only occurs if you expressly give consent to this data processing (via our consent banner on the website). The legal basis for this processing is consent Art. 6(1)(a) GDPR. Without your consent, data processing in the manner described above will not takeplace. If you revoke your consent (e.g. via the consent banner or other options provided on this website), we will stop this data processing. The lawfulness of the processing carried out until the revocation remains unaffected.
We use the service on our website Google APIs. The provider of the service is the Google Ireland Limited, Gordon House, BarrowStreet, Dublin 4, Ireland.
The use of the service may result in data transfer to a third country (USA). The provider is certified according to the EU-U.S. DataPrivacy Framework and therefore offers an appropriate level of data protection.
Further information can be found in the provider's data protection information at the following URL:
https://business.safety.google/privacy
We integrate audio files and videos into our website. These are retrieved from the server of our provider, the so-called audio or video platform. In order to be able to play an audio file or a video, your end device establishes a connection with the audio or video platform and transmits personal data to it. This includes in particular your IP address and any location data or information about your browser and end device.
Processing only occurs if you expressly give consent to this data processing (via our consent banner on the website). The legal basis for this processing is consent Art. 6(1)(a) GDPR. Without your consent, data processing in the manner described above will not take place. If you revoke your consent (e.g. via the consent banner or other options provided on this website), we will stop this dataprocessing. The lawfulness of the processing carried out until the revocation remains unaffected.
We use the service on our website YouTube. The provider of the service is the Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
The use of the service may result in data transfer to a third country (USA). The provider is certified according to the EU-U.S. Data Privacy Framework and therefore offers an appropriate level of data protection.
Further information can be found in the provider's data protection information at the following URL:
https://business.safety.google/privacy
This site uses so-called web fonts for the uniform display of fonts, which are provided by an external provider and loaded by the browser when the website is accessed. When web fonts are loaded, the web font provider becomes aware that our website has been accessed from your IP address, as your browser establishes a direct connection to the web font provider.
Processing only occurs if you expressly give consent to this data processing (via our consent banner on the website). The legal basisfor this processing is consent Art. 6 (1) (a) GDPR. Without your consent, data processing in the manner described above will not takeplace. If you revoke your consent (e.g. via the consent banner or other options provided on this website), we will stop this dataprocessing. The lawfulness of the processing carried out until the revocation remains unaffected.
We use the service on our website Google Fonts. The provider of the service is the Google Ireland Limited, Gordon House, BarrowStreet, Dublin 4, Ireland.
The use of the service may result in data transfer to a third country (USA). The provider is certified according to the EU-U.S. Data Privacy Framework and therefore offers an appropriate level of data protection.
Further information can be found in the provider's data protection information at the following URL:
https://business.safety.google/privacy
You have the option to contact us via a form on the website. In order to contact to be established via this form, we need your contactdetails in particular.
The legal basis for data processing here is to fulfil a contract or pre-contractual measures in accordance with Article 6 (1) (b) GDPR .There may also be a legitimate interest in maintaining business relationships or answering your request for other reasons.
In this case, the legal basis for the processing of your data would be Article 6 (1) (f) GDPR.
The data will be deleted when we have resolved your request and no other retention obligations apply.
We have provided a telephone number and email address on our website in accordance with legal requirements. Data transmitted inthis way is automatically stored by us in order to process the corresponding enquiries or to be able to contact the person making theenquiry. We will not pass this data on to third parties without your consent.
If contact is made by telephone or via our email address for pre-contractual or contractual purposes, the legal basis for the processingof personal data is Article 6(1)(b) GDPR. For all other contact you make, the legal basis for our processing of your personal data is ourlegitimate interest in accordance with Article 6 (1) (f) GDPR.
You have the option to send us an application (e.g. by post, online application form or by email). We will store and process the personal data obtained in this way in order to process your application.
The legal basis for processing is Article 6 (1) (b) GDPR as well as Article 6 (1) (a) GDPR, provided consent has been given. Insofar as German law is applicable, § 26 of the German Federal Data Protection Act (Bundesschutzgesetz, BDSG) in particular is used as the legal basis for processing. You can revoke your consent at any time. The lawfulness of the processing carried out prior to the revocation of consent remains unaffected.
If an employment relationship results from the application, the data collected will be stored for the purpose of processing theemployment relationship on the basis of Article 6 (1) (b) GDPR.If no employment relationship results from the application, the data willbe stored on the basis of Article 6 (1) (f) GDPR for the duration of the statutory claims, in particular due to discrimination in theapplication process.
This is necessary to defend against potential legal action or allegations. If consent has been given, the data will bestored for a longer period on the basis of Article 6 (1) (a) GDPR. You can revoke your consent at any time. The lawfulness of the processing carried out prior to the revocation of consent remains unaffected.
If no employment relationship is established, the person applying may be included in our applicant pool, in which case the details oftheir application will be saved so that they can be contacted in the event of suitable job vacancies arising.
Data is only stored in the applicant pool after consent has been given on the basis of Article 6 (1) (a) GDPR. This consent can be revoked at any time, after which the corresponding data will be deleted, provided there are no legal reasons for retention. Deletiontakes place automatically no later than two years after consent has been given. The lawfulness of the processing carried out prior to the revocation of consent remains unaffected.
Social networks process personal data of their users on a large scale. Visiting our profiles on such networks leads to the processing of your IP address and other information about the used devices, among other things, which enables the IP addresses to be reassigned to individual users. We cannot influence this data processing. Therefore we have to point out that visiting our profiles on the socialnetworks and using their functions is at your own risk. Details on data processing can be found in the operator's data protectiondeclaration.
We have a profile on Facebook. The provider of this service is Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand CanalHarbour, Dublin 2, Ireland.
Detailed information about the handling of personal data can be found in the following data protection declaration of Facebook:
https://www.facebook.com/about/privacy/
.
The purpose of our profiles on social media platforms is to increase our Internet presence and the associated greater notoriety.Therefore, legitimate interest in accordance with Article 6 (1) (f) GDPR is to be used as the legal basis. Furthermore, with regard to the processing activities by the social networks, we refer to their own legal bases (e.g. consent in accordance with Article 6 (1)(a) GDPR), which can be found in the respective data protection declaration.
Together with the social media platform, we are responsible for the data processing operations triggered when you visit our profile. Youcan therefore assert your rights as a data subject in accordance with the GDPR against the social media platform and against us. However, we would like to point out that we cannot influence the processing of data by the social media platform.
Social networks process personal data of their users on a large scale. Visiting our profiles on such networks leads to the processing ofyour IP address and other information about the used devices, among other things, which enables the IP addresses to be reassignedto individual users. We cannot influence this data processing. Therefore we have to point out that visiting our profiles on the socialnetworks and using their functions is at your own risk. Details on data processing can be found in the operator's data protectiondeclaration.
We have a profile on LinkedIn. The provider of this service is LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin2, Ireland. LinkedIn uses advertising cookies.
Detailed information about the handling of personal data can be found in the following data protection declaration of LinkedIn:
https://www.linkedin.com/legal/privacy-policy
.
The purpose of our profiles on social media platforms is to increase our Internet presence and the associated greater notoriety. Therefore, legitimate interest in accordance with Article 6 (1) (f) GDPR is to be used as the legal basis. Furthermore, with regard to theprocessing activities by the social networks, we refer to their own legal bases (e.g. consent in accordance with Article 6 (1) (a) GDPR),which can be found in the respective data protection declaration.
Together with the social media platform, we are responsible for the data processing operations triggered when you visit our profile. You can therefore assert your rights as a data subject in accordance with the GDPR against the social media platform and against us. However, we would like to point out that we cannot influence the processing of data by the social media platform.
Social networks process personal data of their users on a large scale. Visiting our profiles on such networks leads to the processing ofyour IP address and other information about the used devices, among other things, which enables the IP addresses to be reassigned to individual users. We cannot influence this data processing. Therefore we have to point out that visiting our profiles on the socialnetworks and using their functions is at your own risk. Details on data processing can be found in the operator's data protectiondeclaration.
We have a profile on XING. The provider of this service is New Work SE, Dammtorstraße 30, 20354 Hamburg, Germany.
Detailed information about the handling of personal data can be found in the following data protection declaration of XING:
https://privacy.xing.com/de/datenschutzerklaerung
.
The purpose of our profiles on social media platforms is to increase our Internet presence and the associated greater notoriety.Therefore, legitimate interest in accordance with Article 6 (1) (f) GDPR is to be used as the legal basis. Furthermore, with regard to theprocessing activities by the social networks, we refer to their own legal bases (e.g. consent in accordance with Article 6 (1) (a) GDPR), which can be found in the respective data protection declaration.
Together with the social media platform, we are responsible for the data processing operations triggered when you visit our profile. Youcan therefore assert your rights as a data subject in accordance with the GDPR against the social media platform and against us.However, we would like to point out that we cannot influence the processing of data by the social media platform.
Social networks process personal data of their users on a large scale. Visiting our profiles on such networks leads to the processing ofyour IP address and other information about the used devices, among other things, which enables the IP addresses to be reassigned to individual users. We cannot influence this data processing. Therefore we have to point out that visiting our profiles on the social networks and using their functions is at your own risk. Details on data processing can be found in the operator's data protection declaration.
We have a profile on YouTube. The provider of this service is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Detailed information about the handling of personal data can be found in the following data protection declaration of YouTube:
https://policies.google.com/privacy?hl=de
.
The purpose of our profiles on social media platforms is to increase our Internet presence and the associated greater notoriety.Therefore, legitimate interest in accordance with Article 6 (1) (f) GDPR is to be used as the legal basis. Furthermore, with regard to theprocessing activities by the social networks, we refer to their own legal bases (e.g. consent in accordance with Article 6 (1) (a) GDPR),which can be found in the respective data protection declaration.
Together with the social media platform, we are responsible for the data processing operations triggered when you visit our profile. You can therefore assert your rights as a data subject in accordance with the GDPR against the social media platform and against us. However, we would like to point out that we cannot influence the processing of data by the social media platform.
Google also transfers and processes data in the USA. There is currently no adequate level of protection for data transfers to the USA.For this reason, there are risks when processing the data. Whatsapp uses standard contractual clauses and is part of the Data Privacy Framework, whereby Google undertakes to ensure an adequate level of data protection.