Privacy Policy 2026
Privacy Policy 2026
Anexia Holding GmbH
Anexia Holding GmbH
Feldkirchner Straße 140, 9020 Klagenfurt
Austria
Protecting your personal data matters to us. On this page, we explain in plain language which data Anexia Holding GmbH processes when you visit and use this website, why we need it, who we share it with, and when we delete it. Recipients are named by category (Art. 13(1)(e) GDPR). The terms used correspond to the definitions of the General Data Protection Regulation (GDPR).
Content:
- Controller
- Data Protection Officer
- Deletion and retention of data
- Data transfers to third countries
- Automated decision-making
- Privacy settings (consent management)
Content in Detail:
Controller
The controller responsible for the data processing described on this page is:
Anexia Holding GmbH
Feldkirchner Straße 140
9020 Klagenfurt
Austria
Phone: +43-50-556
Data Protection Officer
For all questions relating to data protection, you can reach our Data Protection Officer at data-protection@anexia-it.com.
Deletion and retention of data
We store your data only for as long as we need it for the respective purpose. After that, we delete it — unless statutory retention obligations require otherwise. How long we retain data in each individual case is stated in the relevant section of this policy.
Data transfers to third countries
When you use the appointment scheduler provided by Pipedrive OÜ (Estonia), personal data may be transferred to the USA through sub-processors used by Pipedrive. These transfers are covered by an adequacy decision of the European Commission based on the participation of the providers concerned in the Data Privacy Framework; in addition, Standard Contractual Clauses have been agreed. Beyond this, we do not transfer any personal data to third countries via this website.
Automated decision-making
We do not carry out any decision-making based solely on automated processing, including profiling, within the meaning of Art. 22 GDPR.
Privacy settings (consent management)
With your consent, Anexia Holding GmbH processes usage data and loads external services for statistics, interactive maps, and appointment scheduling. You can withdraw your consent at any time and without giving reasons via the Privacy Link on this website, where you can also change your selection. Withdrawal takes effect for the future; the lawfulness of processing carried out before withdrawal remains unaffected.
Technically necessary (always active): The consent management tool stores your selection and the time of your decision locally on your device until you change your selection or delete your browser data. No data is transferred to third parties in the process.
The legal bases are, for storing your selection, strict technical necessity and our legal obligation to demonstrate consent; for the consent-based services, your consent.
Content:
- Operation of the website
- Statistics (web analytics)
- Appointment scheduling (Pipedrive)
- Interactive maps (VersaTiles)
- Contact and enquiries
- Application process
Content in detail:
Operation of the website
When you access this website, we automatically process the technical data transmitted by your browser (in particular your IP address, date and time of access, page accessed, referrer, browser type, and operating system) in order to deliver the website, ensure its stability and security, and defend against attacks. The website is operated on infrastructure of affiliated companies of the Anexia Group acting as processors on our behalf. We delete server log data no later than XXX days after collection; beyond this, records relating to security incidents are retained until the incident has been fully resolved.
The legal basis is our legitimate interest in the secure and stable operation of the website.
Statistics (web analytics)
With your consent, we record page views and technical usage data so that we can statistically analyse the use of the website and improve our services. The analysis is carried out in aggregated form; we do not create profiles of individual visitors. You can withdraw your consent at any time via the privacy settings.
The legal basis is your consent.
Appointment scheduling (Pipedrive)
With your consent, we load the appointment scheduler of Pipedrive OÜ (Estonia), which you can use to book appointments with us. In doing so, your IP address and technical connection data in particular are transmitted to Pipedrive; if you book an appointment, we additionally process the contact and appointment details you provide. Pipedrive acts as a processor on our behalf; for possible transfers to the USA through sub-processors, see the section "Data transfers to third countries". We delete appointment data as soon as it is no longer required for handling the appointment and any follow-up.
The legal bases are your consent for loading the service and the performance of pre-contractual measures for handling the appointment. This processing is carried out under joint controllership between Anexia Holding GmbH and the subsidiary to which your appointment request is directed. In this context, Anexia Holding GmbH is responsible for the technical provision via this website, while the subsidiary is responsible for handling and conducting the appointment.*
Interactive maps (VersaTiles)
With your consent, we retrieve map styles and map tiles from VersaTiles in order to display interactive maps. In doing so, your IP address and technical connection data in particular are transmitted to VersaTiles. You can withdraw your consent at any time via the privacy settings.
The legal basis is your consent.
Contact and enquiries
If you contact us via the contact form, by email, or by phone, we process your master data and the content of your message (communication data) in order to handle your enquiry. How long we retain this data depends on the nature of your request: we delete it once the purpose has been fulfilled and review open matters regularly for continued necessity; enquiries relevant to contracts or legal matters are transferred to the respective contract or legal file.
The legal basis is — depending on the nature of your request — Art. 6(1)(b) or (f) GDPR.
Application process
If you apply for a position with us, we process your master data and applicant data to manage your application and carry out the application process. For this purpose, we use a specialised applicant management system (OnlyFy) under joint controllership with New Work SE. Your documents are automatically deleted nine months after the end of the application process.
The legal bases are pre-contractual measures taken at your request and our legitimate interest in defending against legal claims under equal treatment legislation.
Content:
- Your rights as a data subject
- Right to lodge a complaint with the supervisory authority
Content in detail:
Your rights as a data subject
You have the right at any time to:
- Access the data stored about you (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Object to processing based on legitimate interests (Art. 21 GDPR)
- Withdraw consent with effect for the future (Art. 7(3) GDPR) — the lawfulness of processing carried out before withdrawal remains unaffecte
To exercise these rights, simply contact us or our Data Protection Officer directly using the contact details provided above.
Right to lodge a complaint with the supervisory authority
You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR) — at your choice, in particular with the supervisory authority of the Member State of your habitual residence, your place of work, or the place of the alleged infringement. An overview of all European supervisory authorities is available from the European Data Protection Board: https://www.edpb.europa.eu/about-edpb/about-edpb/members_en
The supervisory authority responsible for us is:
Austrian Data Protection Authority (Österreichische Datenschutzbehörde)
Barichgasse 40-42
1030 Vienna
Anexia Cloud Solutions GmbH – Austria
Anexia Cloud Solutions GmbH
Feldkirchner Straße 140, 9020 Klagenfurt
Austria
Protecting your personal data matters to us. On this page, we explain in plain language which data Anexia Cloud Solutions GmbH processes in the course of its business as a provider of IaaS, cloud, and managed services, why we need it, who we share it with, and when we delete it. Recipients are named by category (Art. 13(1)(e) GDPR). The terms used correspond to the definitions of the General Data Protection Regulation (GDPR).
Content:
- Controller
- Data Protection Officer
- Deletion and retention of data
- Data transfers to third countries
- Automated decision-making
Content in detail:
Controller
The controller responsible for the data processing described on this page is:
Anexia Cloud Solutions GmbH
Feldkirchner Straße 140
9020 Klagenfurt
Austria
Phone: +43-50-556
Data Protection Officer
For all questions relating to data protection, you can reach our Data Protection Officer at data-protection@anexia-it.com.
Deletion and retention of data
We store your data only for as long as we need it for the respective purpose. After that, we delete it — unless statutory retention obligations require otherwise. How long we retain data in each individual case is stated in the relevant section of this policy.
Data transfers to third countries
We use Microsoft Teams and Microsoft 365. Despite the selected EU data location, personal data may be transferred to the USA. These transfers are covered by an adequacy decision of the European Commission based on the participation of Microsoft Corporation in the Data Privacy Framework. In addition, Standard Contractual Clauses have been agreed with Microsoft for the data transfer.
Automated decision-making
We do not carry out any decision-making based solely on automated processing, including profiling, within the meaning of Art. 22 GDPR.
Content:
- Contact and enquiries
- Offers and contract initiation (opportunity management)
- Contract performance and customer account
- Infrastructure-as-a-Service (IaaS), cloud & managed services
- Invoicing and financial accounting (invoicing, financial services)
- Contract management and data processing agreements
- Purchasing and procurement
- Application process
- Whistleblowing system
Content in detail:
Contact and enquiries
If you contact us via the contact form, by email, phone, or fax, we process your master data and the content of your message (communication data) in order to handle your enquiry. How long we retain this data depends on the nature of your request: we delete it once the purpose has been fulfilled and review open matters annually for continued necessity; enquiries relevant to contracts or legal matters are transferred to the respective contract or legal file.
The legal basis is — depending on the nature of your request — Art. 6(1)(b) or (f) GDPR.
Offers and contract initiation (opportunity management)
From the first enquiry by a prospect or existing customer through to the preparation of offers or contracts and the conclusion of negotiations, we process master data, contract, payment, and bank data, as well as other project-specific data. Affiliated companies of the Anexia Group and external sales tools support us as processors. We store this data for three years from the completion of the handling of your enquiry.
The legal bases are the performance or initiation of a contract and our legitimate interest in handling customer enquiries.
Contract performance and customer account
To carry out pre-contractual measures, fulfil our contractual obligations, and manage your customer account, we process your master data, contract data, access data, and payment, invoicing, and accounting data. After termination or fulfilment of all contracts, we delete your data as soon as we no longer need it to defend against or assert legal claims; statutory retention periods remain unaffected. Providing this data is necessary for concluding the contract — without it, we cannot enter into the contract or provide our services.
The legal basis is Art. 6(1)(b) GDPR (performance of a contract).
Infrastructure-as-a-Service (IaaS), cloud & managed services
In the course of providing our IaaS, cloud, and managed services, we process personal data of our customers and their clients. This includes, among other things, contact information, billing and payment data, call notes, and other information required for the performance of the contract, such as technical descriptions or support communications. This data is only passed on to external service providers, such as payment providers or data centre operators, where this is necessary to fulfil our contractual obligations.
We retain personal data only for as long as is necessary for the purposes for which it was collected. This includes the provision of our services, the handling of operational processes, and compliance with statutory, contractual, and regulatory requirements. As soon as the data is no longer needed for these purposes, it is securely deleted or anonymised.
The legal bases are the performance of a contract with the data subject or the implementation of pre-contractual measures (Art. 6(1)(b) GDPR) and our legitimate interest in defending against legal claims.
Invoicing and financial accounting (invoicing, financial services)
For invoicing and our financial processes (accounts receivable and payable, asset accounting, group accounting, general ledger, and treasury), we process master, contract, and bank data as well as payment, invoicing, and accounting data. Affiliated companies of the Anexia Group act as processors. We retain these records for seven years from the end of the calendar year in which the respective invoice was posted or the task was completed.
The legal basis is our statutory obligation under the Austrian Federal Fiscal Code (BAO).
Contract management and data processing agreements
We create, manage, and archive contracts with customers, suppliers, and partners — including data processing agreements (DPAs) and non-disclosure agreements (NDAs) — together with the associated master and contract data in a dedicated sales tool (processing on our behalf). For electronic signatures, we use specialised providers as processors. We retain contract documents for the duration of the contractual relationship plus 30 years.
The legal bases are the performance of a contract and our legitimate interest in documentation for defending against or asserting legal claims.
Purchasing and procurement
Our procurement processes ensure the needs-based and economical supply of goods and services — from purchasing through goods receipt to invoice verification, including article master data, supplier evaluation, and delivery locations. In doing so, we process master data of our suppliers and their contact persons as well as contract, payment, and performance data. Affiliated companies of the Anexia Group support us as processors. We retain procurement records for seven years from the end of the calendar year in which the respective transaction was completed.
The legal bases are the performance of a contract and our statutory obligations.
Application process
If you apply for a position with us, we process your master data and applicant data to manage your application and carry out the application process. For this purpose, we use a specialised applicant management system (OnlyFy) under joint controllership with New Work SE. Your documents are automatically deleted nine months after the end of the application process.
The legal bases are pre-contractual measures taken at your request and our legitimate interest in defending against legal claims under equal treatment legislation (Art. 6(1)(b) and (f) GDPR).
Whistleblowing system
Violations of the law can be reported via our whistleblowing system. We process the report together with contact details, correspondence, and internal documentation — as well as further personal data depending on the individual case — in order to receive reports, examine their validity, and prevent or sanction violations of the law. This concerns both reporting persons and persons affected by a report. Affiliated companies of the Anexia Group are involved as processors. We retain the records for five years from the last processing of the report or the conclusion of proceedings.
The legal basis is compliance with our legal obligations under whistleblower protection legislation (Art. 6(1)(c) GDPR).
Content:
- Your rights as a data subject
- Right to lodge a complaint with the supervisory authority
Content in Detail:
Your rights as a data subject
You have the right at any time to:
- Access the data stored about you (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Object to processing based on legitimate interests (Art. 21 GDPR)
- Withdraw consent with effect for the future (Art. 7(3) GDPR) — the lawfulness of processing carried out before withdrawal remains unaffected
To exercise these rights, simply contact us or our Data Protection Officer directly using the contact details provided above.
Right to lodge a complaint with the supervisory authority
You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR) — at your choice, in particular with the supervisory authority of the Member State of your habitual residence, your place of work, or the place of the alleged infringement. An overview of all European supervisory authorities is available from the European Data Protection Board: https://www.edpb.europa.eu/about-edpb/about-edpb/members_en
The supervisory authority responsible for us is:
Austrian Data Protection Authority (Österreichische Datenschutzbehörde)
Barichgasse 40-42
1030 Vienna
Anexia Digital Engineering GmbH – Austria
Anexia Digital Engineering GmbH
Feldkirchner Straße 140, 9020 Klagenfurt
Austria
Protecting your personal data matters to us. On this page, we explain in plain language which data Anexia Digital Engineering GmbH processes in the course of its business as a digital engineering service provider, why we need it, who we share it with, and when we delete it. Recipients are named by category (Art. 13(1)(e) GDPR). The terms used correspond to the definitions of the General Data Protection Regulation (GDPR).
Content:
- Controller
- Data Protection Officer
- Deletion and retention of data
- Data transfers to third countries
- Automated decision-making
Content in detail:
Controller
The controller responsible for the data processing described on this page is:
Anexia Digital Engineering GmbH
Feldkirchner Straße 140
9020 Klagenfurt
Austria
Phone: +43-50-556
Data Protection Officer
For all questions relating to data protection, you can reach our Data Protection Officer at data-protection@anexia-it.com.
Deletion and retention of data
We store your data only for as long as we need it for the respective purpose. After that, we delete it — unless statutory retention obligations require otherwise. How long we retain data in each individual case is stated in the relevant section of this policy.
Data transfers to third countries
We use Microsoft Teams and Microsoft 365. Despite the selected EU data location, personal data may be transferred to the USA. These transfers are covered by an adequacy decision of the European Commission based on the participation of Microsoft Corporation in the Data Privacy Framework. In addition, Standard Contractual Clauses have been agreed with Microsoft for the data transfer.
Automated decision-making
We do not carry out any decision-making based solely on automated processing, including profiling, within the meaning of Art. 22 GDPR.
Content:
- Contact and enquiries
- Offers and contract initiation (opportunity management)
- Contract performance and customer account
- Customer software projects (custom software development)
- Invoicing and financial accounting (invoicing, financial services)
- Contract management and data processing agreements
- Purchasing and procurement
- Application process
- Whistleblowing system
Content in detail:
Contact and enquiries
If you contact us via the contact form, by email, phone, or fax, we process your master data and the content of your message (communication data) in order to handle your enquiry. How long we retain this data depends on the nature of your request: we delete it once the purpose has been fulfilled and review open matters annually for continued necessity; enquiries relevant to contracts or legal matters are transferred to the respective contract or legal file.
The legal basis is — depending on the nature of your request — Art. 6(1)(b) or (f) GDPR.
Offers and contract initiation (opportunity management)
From the first enquiry by a prospect or existing customer through to the preparation of offers or contracts and the conclusion of negotiations, we process master data, contract, payment, and bank data, as well as other project-specific data. Affiliated companies of the Anexia Group and external sales tools support us as processors. We store this data for three years from the completion of the handling of your enquiry.
The legal bases are the performance or initiation of a contract and our legitimate interest in handling customer enquiries.
Contract performance and customer account
To carry out pre-contractual measures, fulfil our contractual obligations, and manage your customer account, we process your master data, contract data, access data, and payment, invoicing, and accounting data. After termination or fulfilment of all contracts, we delete your data as soon as we no longer need it to defend against or assert legal claims; statutory retention periods remain unaffected. Providing this data is necessary for concluding the contract — without it, we cannot enter into the contract or provide our services.
The legal basis is Art. 6(1)(b) GDPR (performance of a contract).
Customer software projects (custom software development)
The core of our business is the development of custom software on behalf of our customers. In addition to master, contract, payment, and bank data, we process internal company data as well as other project-specific personal data to the extent it arises in the respective project. The results of this process are the developed software, automated tests, deployment playbooks, and the software documentation. We use affiliated companies of the Anexia Group as processors. We store project data for 30 years — until the absolute limitation period for damages claims expires — from the handover of the developed software to the customer.
The legal bases are the execution of the customer order (performance of a contract) and our legitimate interest in defending against legal claims.
Invoicing and financial accounting (invoicing, financial services)
For invoicing and our financial processes (accounts receivable and payable, asset accounting, group accounting, general ledger, and treasury), we process master, contract, and bank data as well as payment, invoicing, and accounting data. Affiliated companies of the Anexia Group act as processors. We retain these records for seven years from the end of the calendar year in which the respective invoice was posted or the task was completed.
The legal basis is our statutory obligation under the Austrian Federal Fiscal Code (BAO).
Contract management and data processing agreements
We create, manage, and archive contracts with customers, suppliers, and partners — including data processing agreements (DPAs) and non-disclosure agreements (NDAs) — together with the associated master and contract data in a dedicated sales tool (processing on our behalf). For electronic signatures, we use specialised providers as processors. We retain contract documents for the duration of the contractual relationship plus 30 years.
The legal bases are the performance of a contract and our legitimate interest in documentation for defending against or asserting legal claims.*
Purchasing and procurement
Our procurement processes ensure the needs-based and economical supply of goods and services — from purchasing through goods receipt to invoice verification, including article master data, supplier evaluation, and delivery locations. In doing so, we process master data of our suppliers and their contact persons as well as contract, payment, and performance data. Affiliated companies of the Anexia Group support us as processors. We retain procurement records for seven years from the end of the calendar year in which the respective transaction was completed.
The legal bases are the performance of a contract and our statutory obligations.
Application process
If you apply for a position with us, we process your master data and applicant data to manage your application and carry out the application process. For this purpose, we use a specialised applicant management system (OnlyFy) under joint controllership with New Work SE. Your documents are automatically deleted nine months after the end of the application process.
The legal bases are pre-contractual measures taken at your request and our legitimate interest in defending against legal claims under equal treatment legislation (Art. 6(1)(b) and (f) GDPR).
Whistleblowing system
Violations of the law can be reported via our whistleblowing system. We process the report together with contact details, correspondence, and internal documentation — as well as further personal data depending on the individual case — in order to receive reports, examine their validity, and prevent or sanction violations of the law. This concerns both reporting persons and persons affected by a report. Affiliated companies of the Anexia Group are involved as processors. We retain the records for five years from the last processing of the report or the conclusion of proceedings.
The legal basis is compliance with our legal obligations under whistleblower protection legislation (Art. 6(1)(c) GDPR).
Anexia Cloud Solutions GmbH – Germany
Anexia Cloud Solutions GmbH
Emmy-Noether-Straße 10, 76131 Karlsruhe
Germany
Protecting your personal data matters to us. On this page, we explain in plain language which data Anexia Cloud Solutions GmbH processes in the course of its business as a provider of IaaS, cloud, and managed services, why we need it, who we share it with, and when we delete it. Recipients are named by category (Art. 13(1)(e) GDPR). The terms used correspond to the definitions of the General Data Protection Regulation (GDPR).
Content:
- Controller
- Data Protection Officer
- Deletion and retention of data
- Data transfers to third countries
- Automated decision-making
Content in detail:
Controller
The controller responsible for the data processing described on this page is:
Anexia Cloud Solutions GmbH**
Emmy-Noether-Straße 10
76131 Karlsruhe
Germany
Phone: +43-50-556
Data Protection Officer
For all questions relating to data protection, you can reach our Data Protection Officer at data-protection@anexia-it.com.
Deletion and retention of data
We store your data only for as long as we need it for the respective purpose. After that, we delete it — unless statutory retention obligations require otherwise. How long we retain data in each individual case is stated in the relevant section of this policy.
Data transfers to third countries
We use Microsoft Teams and Microsoft 365. Despite the selected EU data location, personal data may be transferred to the USA. These transfers are covered by an adequacy decision of the European Commission based on the participation of Microsoft Corporation in the Data Privacy Framework. In addition, Standard Contractual Clauses have been agreed with Microsoft for the data transfer.
Automated decision-making
We do not carry out any decision-making based solely on automated processing, including profiling, within the meaning of Art. 22 GDPR.
Content:
- Contact and enquiries
- Offers and contract initiation (opportunity management)
- Contract performance and customer account
- Infrastructure-as-a-Service (IaaS), cloud & managed services
- Invoicing and financial accounting (invoicing, financial services)
- Contract management and data processing agreements
- Purchasing and procurement
- Application process
- Whistleblowing system
Content in detail:
Contact and enquiries
If you contact us via the contact form, by email, phone, or fax, we process your master data and the content of your message (communication data) in order to handle your enquiry. How long we retain this data depends on the nature of your request: we delete it once the purpose has been fulfilled and review open matters annually for continued necessity; enquiries relevant to contracts or legal matters are transferred to the respective contract or legal file.
The legal basis is — depending on the nature of your request — Art. 6(1)(b) or (f) GDPR.
Offers and contract initiation (Opportunity Management)
From the first enquiry by a prospect or existing customer through to the preparation of offers or contracts and the conclusion of negotiations, we process master data, contract, payment, and bank data, as well as other project-specific data. Affiliated companies of the Anexia Group and external sales tools support us as processors. We store this data for three years from the completion of the handling of your enquiry.
The legal bases are the performance or initiation of a contract and our legitimate interest in handling customer enquiries.
Contract performance and customer account
To carry out pre-contractual measures, fulfil our contractual obligations, and manage your customer account, we process your master data, contract data, access data, and payment, invoicing, and accounting data. After termination or fulfilment of all contracts, we delete your data as soon as we no longer need it to defend against or assert legal claims; statutory retention periods remain unaffected. Providing this data is necessary for concluding the contract — without it, we cannot enter into the contract or provide our services.
The legal basis is Art. 6(1)(b) GDPR (performance of a contract).
Infrastructure-as-a-Service (IaaS), cloud & managed services
In the course of providing our IaaS, cloud, and managed services, we process personal data of our customers and their clients. This includes, among other things, contact information, billing and payment data, call notes, and other information required for the performance of the contract, such as technical descriptions or support communications. This data is only passed on to external service providers, such as payment providers or data centre operators, where this is necessary to fulfil our contractual obligations.
We retain personal data only for as long as is necessary for the purposes for which it was collected. This includes the provision of our services, the handling of operational processes, and compliance with statutory, contractual, and regulatory requirements. As soon as the data is no longer needed for these purposes, it is securely deleted or anonymised.
The legal bases are the performance of a contract with the data subject or the implementation of pre-contractual measures (Art. 6(1)(b) GDPR) and our legitimate interest in defending against legal claims.
Invoicing and financial accounting (invoicing, financial services)
For invoicing and our financial processes (accounts receivable and payable, asset accounting, group accounting, general ledger, and treasury), we process master, contract, and bank data as well as payment, invoicing, and accounting data. Affiliated companies of the Anexia Group act as processors. We retain these records for seven years from the end of the calendar year in which the respective invoice was posted or the task was completed.
The legal basis is our statutory obligation under the German Fiscal Code (AO) and the German Commercial Code (HGB).
Contract management and data processing agreements
We create, manage, and archive contracts with customers, suppliers, and partners — including data processing agreements (DPAs) and non-disclosure agreements (NDAs) — together with the associated master and contract data in a dedicated sales tool (processing on our behalf). For electronic signatures, we use specialised providers as processors. We retain contract documents for the duration of the contractual relationship plus 30 years.
The legal bases are the performance of a contract and our legitimate interest in documentation for defending against or asserting legal claims.
Purchasing and procurement
Our procurement processes ensure the needs-based and economical supply of goods and services — from purchasing through goods receipt to invoice verification, including article master data, supplier evaluation, and delivery locations. In doing so, we process master data of our suppliers and their contact persons as well as contract, payment, and performance data. Affiliated companies of the Anexia Group support us as processors. We retain procurement records for seven years from the end of the calendar year in which the respective transaction was completed.
The legal bases are the performance of a contract and our statutory obligations.
Application process
If you apply for a position with us, we process your master data and applicant data to manage your application and carry out the application process. For this purpose, we use a specialised applicant management system (OnlyFy) under joint controllership with New Work SE. Your documents are automatically deleted nine months after the end of the application process.
The legal bases are pre-contractual measures taken at your request and our legitimate interest in defending against legal claims under equal treatment legislation (Art. 6(1)(b) and (f) GDPR).
Whistleblowing system
Violations of the law can be reported via our whistleblowing system. We process the report together with contact details, correspondence, and internal documentation — as well as further personal data depending on the individual case — in order to receive reports, examine their validity, and prevent or sanction violations of the law. This concerns both reporting persons and persons affected by a report. Affiliated companies of the Anexia Group are involved as processors. We retain the records for five years from the last processing of the report or the conclusion of proceedings.
The legal basis is compliance with our legal obligations under whistleblower protection legislation (Art. 6(1)(c) GDPR).
Content:
- Your rights as a data subject
- Right to lodge a complaint with the supervisory authority
Content in Detail:
Your rights as a data subject
You have the right at any time to:
- Access the data stored about you (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Object to processing based on legitimate interests (Art. 21 GDPR)
- Withdraw consent with effect for the future (Art. 7(3) GDPR) — the lawfulness of processing carried out before withdrawal remains unaffected
To exercise these rights, simply contact us or our Data Protection Officer directly using the contact details provided above.
Right to lodge a complaint with the supervisory authority
You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR) — at your choice, in particular with the supervisory authority of the Member State of your habitual residence, your place of work, or the place of the alleged infringement. An overview of all European supervisory authorities is available from the European Data Protection Board: https://www.edpb.europa.eu/about-edpb/about-edpb/members_en
The supervisory authority responsible for us is:
The State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg (Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg)
Heilbronner Straße 35
70191 Stuttgart
https://www.baden-wuerttemberg.datenschutz.de