GBA GROUP Data Protection Notice for Customers and Potential Customers Instructions
- June 3, 2024
- GBA GROUP
Table of Contents
GBA GROUP Data Protection Notice for Customers and Potential Customers
Data Protection Notice for Customers and Potential Customers
(Updated 14 Jan 2021)
Protecting your privacy is an important matter for the GBA Group. We process
personal information confidentially and only in accordance with legal
regulations.
In the following, we would like to provide you with information about the
personal data that we collect during our cooperation with each other and how
that data is processed.
Who is responsible for the data processing?
The individual contractual partner within the GBA Group is responsible for
processing your data.
The central contact is GBA Holding GmbH, Goldtschmidtstraße 5, 21073 Hamburg,
Germany, represented by Steffen Walter.
Contact information for all of the companies in the GBA Group as well as for
the responsible Data Protection Officers can be found here.
Why is personal data processed and what is the legal basis for it?
The legal basis for processing this data is Article 6 paragraph 1, letter b of
the GDPR, a contract between you as the data subject and us as the responsible
party, including the steps leading up to the formation of a contract, insofar
as these are requested by you. It is necessary to process personal data to
fulfill the order appropriately and to fulfill our contractual obligations.
Furthermore, there is data that we process on the basis of Article 6 paragraph
1 letter f of the GDPR, a legitimate interest. That includes, for example,
personal data that we process because we have a contractual relationship with
your employer and have been commissioned to perform certain tasks by your
employer. This also includes invoicing our services, which could also
potentially result in the sale of our outstanding claims, based on the
legitimate interest (Art. 6, par. 1 f) in having an efficient claims
management system. Furthermore, we process your data for the purpose of
sending mail and email to advertise our own services, for telephone
acquisitions, and as an important part of our customer service, all within a
legally acceptable scope and based on a legitimate interest in accordance with
the GDPR Art. 6, par. 1 (f). In these cases, our legitimate interest is
economic in nature.
The companies of the GBA Group process your data for the purposes of internal
administration at a centralized location and based on a legitimate interest in
accordance with GDPR Art. 6, par. 1 (f) in conjunction with EEC 48 GDPR.
Furthermore, the legal basis for processing your personal data can also be
your consent, in accordance with GDPR Art. 6 par. 1 (a) or a legal obligation
in accordance with GDPR Art. 6 par. 1 (c).
If you use our customer portal, Prime Net, in order to inquire about your
analytical results, this occurs with your consent in accordance with GDPR Art.
6 par. 1 (a). You have the right to revoke this consent at any time without
affecting the lawfulness of the data processing that took place up until that
point based on your consent.
If we process your data for any other purpose than those mentioned here, you
will be informed about that separately.
Is it necessary for you to provide your data?
Providing your personal data is required for the formation of the contract as
well as for the legal obligations that result from it, insofar as the
cooperation with your company cannot be carried out using, for example, post
office boxes or general telephone numbers.
Registration for the customer portal, Prime Net, is not necessary for the
formation of a contract. However, if you wish to use this service, it is
necessary to provide the required personal data.
How long is the data stored?
Fundamentally, we store your data for as long as it is necessary to fulfill
its purpose. We only save your data beyond this point insofar as we have to
save it in order to fulfill our legal requirements. For example, due to legal
retention periods for tax law and commercial law, we are required to store
documents such as contracts and invoices for a period of 10 years.
Who receives the data?
Within the company as well as in the GBA Group, on principle, only those
individuals who are entrusted with processing your inquiries and orders have
access to your personal data.
If necessary, we may forward your data to the following recipients:
- Tax authorities, auditing authorities, as well as public bodies, if we are convinced in good faith that we are legally bound to forward this data or due to another regulation, or
- Other service providers, e.g., external providers of IT services and storage capacity.
We have entered data processing agreements with our service providers, which
ensure that the data is processed exclusively according to our instructions
and in a permissible way.
Where is the data processed?
Your data is processed exclusively in datacenters in the European Economic
Area. We do not transfer your data to any location outside of the EU member
states.
Your Rights as a Data Subject
You have the right to obtain information about your personal data that we
process.
Furthermore, you have the right to have your personal data rectified or
erased, or to restrict how this data is processed or its transferability, to
the extent that you are entitled to do so by law.
In accordance with GDPR Art. 21 par. 1 sentence 1, as a data subject, you have
the right to object, on grounds relating to your particular situation, at any
time to the processing of your personal data, provided that this processing is
carried out on the legal basis of Article 6, par. 1 (f), (legitimate
interest). Please address your objections to datenschutz@gba-
group.de.
Additionally, you have the right to issue a complaint to the responsible
supervisory authority if you see cause to do so. For GBA sites in Germany, the
responsible supervisory authority is that of the federal state where the
company is located. For companies in the GBA Group not located in Germany, the
respective national supervisory authorities are responsible.
Here you can find a list of the contact information for the German supervisory
authorities as well as the national authorities:
https://www.bfdi.bund.de/DE/Infothek/Anschriften_Links/anschriften_links-
node.html
If you require help selecting the responsible authority, we will gladly assist
you. Please contact: [email protected].
Contact Information
If you want to exercise your rights as a data subject or if you have other
questions regarding data protection at the GBA Group, then please contact our
data protection team at: [email protected].
In this context, especially when exercising your rights as a data subject, we
ask you for your understanding that we may ask you to verify that you are in
fact the person who you claim to be.
Changes to the Data Protection Notice
We reserve the rights to adapt our data protection notice in correspondence to
changes in legal requirements. Therefore, please always refer to the current
version of our data protection notice.