Which privacy notices would you like to see?
General Data Protection InformationApplication processPrivacy Notice on Video Surveillance
General Data Protection Information
Data Controller
The data controller responsible for data processing via this website is:
BHI Biohealth International GmbH
Heinrich-Wirth-Straße 13
95213 Münchberg/Germany
Telephone: +49 (0) 9251 87087-20
Email address: info@biohealth-int.com
Authorised representative: Managing Director Dr Peter Pfeilschifter
Legal notice: www.biohealth-int.com/en/imprint
Data Protection Officer
SBS Data Protect GmbH
Represented by the Managing Director, Thilo Noack
Hans-Henny-Jahnn Weg 49
22085 Hamburg/Germany
Email address: noack@sbs-data.de
Security and protection of your personal data
The confidentiality of your personal data and its protection against unauthorised access are important to us. As the data controller, we are subject to the General Data Protection Regulation (GDPR) and the Federal Data Protection Act (BDSG). We have implemented technical and organisational measures to ensure that data protection requirements are complied with both by us and by the external service providers we use.
Relevant legal bases
The processing of personal data is lawful only if there is a legal basis for it. The following are particularly relevant:
- Consent of the data subject, Article 6(1)(a) of the GDPR
- Performance of a contract or pre-contractual measures, Article 6(1)(b) of the GDPR
- Compliance with a legal obligation, Article 6(1)(c) of the GDPR
- Protection of vital interests, Article 6(1)(d) of the GDPR
- Performance of a task carried out in the public interest, Article 6(1)(e) of the GDPR
- Protection of legitimate interests, provided that the interests or fundamental rights of the data subject do not override them, Article 6(1)(f) of the GDPR
Technical and organisational security measures
We implement appropriate technical and organisational measures, taking into account the state of the art, the costs of implementation and the nature, scope and purposes of the processing, to ensure a level of security appropriate to the risk. These include, in particular, measures to safeguard the confidentiality, integrity and availability of data, as well as procedures for exercising data subjects’ rights, for erasing data and for responding to security incidents. Data protection is taken into account right from the selection of hardware and software (Privacy by Design and Privacy by Default, Article 25 of the GDPR).
Data processing in third countries
Where we process data in a country outside the EU or the EEA (third country), or have data processed there, this is done only where the legal requirements set out in Articles 44 to 49 of the GDPR are met, in particular consent, an adequacy decision by the European Commission, or contractual safeguards in the form of the European Commission’s Standard Contractual Clauses (SCCs).
Collection of personal data when visiting our website
If you use the website purely for information purposes – that is, if you do not register or otherwise provide us with information – we only collect the data that your browser automatically transmits to our server:
- IP address
- Date and time of the request
- Time zone difference from Greenwich Mean Time (GMT)
- Content of the request (page accessed)
- Access status/HTTP status code
- Amount of data transferred
- Website from which the request originates (referrer)
- Browser, operating system and screen resolution
- Language and version of the browser software
This data is deleted immediately following technical analysis. In accordance with Article 6(1)(f) of the GDPR, the collection of this data serves our legitimate interest in ensuring the correct and secure provision of our website.
Cookie Consent Tool
To obtain valid consent for cookies and similar technologies that require consent, we use the consent management tool provided by Usercentrics GmbH, Sendlinger Straße 7, 80331 Munich. When you visit the website, a banner appears allowing you to grant or refuse consent for individual categories of cookies. Until consent has been granted, the tool blocks the setting of all non-essential cookies. To assign and log your consent decision, Usercentrics collects and stores technical information, including your IP address. This processing is carried out on the basis of Article 6(1)(f) of the GDPR (user-friendly, legally compliant consent management) and Article 6(1)(c) of the GDPR, as we, as the data controller, are legally obliged to make the use of non-technically necessary cookies subject to consent.
Legal basis under the Telecommunications, Digital Services and Data Protection Act (TDDDG)
In accordance with Section 25(1) of the TDDDG, your consent is generally required for the storage of information on your terminal equipment or for access to information already stored there; this consent is obtained via the cookie consent tool when you visit the website. No consent is required under Section 25(2) of the TDDDG where the storage or access is strictly necessary for us to provide you with a service you have expressly requested (‘technically necessary cookies’). You can find out which specific cookies these are in the cookie settings. The legal basis for the subsequent processing of the personal data collected in this way is then derived from the GDPR and is specified separately below for the respective services.
Cookies used
This website uses the following categories of cookies and similar technologies (e.g. pixels):
- Strictly necessary cookies (Type a)
- Functional and statistical cookies (Type b)
- Marketing cookies (Type c)
Strictly necessary cookies (Type a)
These first-party cookies ensure functions without which you cannot use the website as intended, such as maintaining a logged-in status across multiple subpages. Their use is permitted without consent in accordance with Section 25(2) of the TDDDG and therefore cannot be disabled individually via the cookie banner. However, you can generally disable cookies in your browser at any time.
Functional and statistical cookies (Type b)
These cookies store information such as your chosen language setting or track how the website is used, for example which subpages are visited, how long users spend on them and which search terms they used to reach the website. As these cookies are not strictly necessary within the meaning of Section 25(2) of the TDDDG, they are only set once you have given your consent via the cookie consent tool. The legal basis is your consent, Article 6(1)(a) of the GDPR in conjunction with Section 25(1) of the TDDDG. You may withdraw your consent at any time with future effect via the cookie consent tool.
Marketing cookies (Type c)
Cookies that are neither strictly necessary (Type a) nor functional/statistical cookies (Type b) are used only with your consent. They are used to display targeted advertising to you based on your usage behaviour. Marketing cookies predominantly originate from external advertising companies (third-party cookies). The legal basis is your consent, Article 6(1)(a) of the GDPR in conjunction with Section 25(1) of the TDDDG.
You can also object to the use of cookies for online advertising via industry-wide opt-out tools, such as www.aboutads.info/choices/ (USA) or www.youronlinechoices.com/uk/your-ad-choices (EU).
You can also configure your browser to generally prevent or prompt you about the setting of cookies, and delete cookies that have already been set at any time. You can find details on this in your browser’s help function.
Google Analytics 4 (GA4)
This website uses Google Analytics 4 (GA4), a web analytics service provided by Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland (“Google”). Google Analytics 4 uses cookies that enable an analysis of how the website is used.
GA4 is designed in such a way that your device’s IP address is used to determine your location but is not stored in full; we are therefore unable to link this to you personally. Within the framework of GA4, we have access to server-side tracking options, subject to your consent, which allow user data to be further pseudonymised before it is transmitted to Google.
On our behalf, Google analyses the data collected, compiles reports on website usage and provides related services. The event data collected via GA4 is stored for a period of 2 or 14 months, as specified by us, and is then automatically deleted.
The ‘demographic characteristics’ feature enables us to analyse the age, gender and interests of user groups across devices without it being possible to identify any specific individual. This data is also deleted after 2 months.
The use of Google Analytics 4 is based solely on your consent, in accordance with Article 6(1)(a) of the GDPR in conjunction with Section 25(1) of the TDDDG. Without your consent, the service will not be used at all. You may withdraw your consent at any time with future effect via the cookie consent tool. A data processing agreement has been entered into with Google in accordance with Article 28 of the GDPR.
For the transfer of data to the USA, Google relies on its certification under the EU-US Data Privacy Framework (https://www.dataprivacyframework.gov/s/participant-search). In addition, Google has agreed to the European Commission’s Standard Contractual Clauses, which apply in the event that the Data Privacy Framework ceases to be valid.
Further information on Google Analytics 4 can be found at policies.google.com/privacy and policies.google.com/technologies/partner-sites.
Google Ads
We use Google Ads, an online advertising service provided by Google Ireland Limited. When you click on an advert displayed by Google, a cookie is set for the purpose of conversion tracking. This cookie expires after 30 days and does not allow for personal identification. Conversion cookies enable Google and us to recognise that an advert has been clicked on and that a specific, pre-defined action has subsequently been carried out.
The legal basis is your consent, Article 6(1)(a) of the GDPR in conjunction with Section 25(1) of the TDDDG. With regard to data transfers to the USA, the provisions relating to the EU-US Data Privacy Framework in the ‘Google Analytics 4’ section apply accordingly. Further information: www.google.de/policies/privacy/.
Google Tag Manager
We use Google Tag Manager to manage the integration of website tags via a central interface. Google Tag Manager itself does not set any cookies and does not process any personal data; it merely triggers tags from other services, to which the legal bases and consent requirements described in the relevant documentation apply.
Our social media presence
Our social media presence:
- https://www.facebook.com/biohealth.international/
- https://www.instagram.com/biohealth.international/?hl=de
- https://www.linkedin.com/company/7256915/admin/dashboard/
- https://www.xing.com/pages/biohealthinternationalgmbh
- https://www.youtube.com/channel/UCx4o7QGfYbdF7ExtsL6phBQ
Data processing by social networks
We maintain publicly accessible profiles on social networks. You can find a list of the specific social networks we use below.
Social networks such as Facebook etc. are generally able to analyse your user behaviour in detail when you visit their website or a website featuring integrated social media content (e.g. ‘Like’ buttons or advertising banners). Visiting our social media pages triggers numerous data-processing operations relevant to data protection. Specifically:
If you are logged into your social media account and visit our social media page, the operator of the social media portal may associate this visit with your user account. However, your personal data may also be collected even if you are not logged in or do not have an account with the relevant social media portal. In this case, data is collected, for example, via cookies stored on your device or by recording your IP address.
Using the data collected in this way, the operators of social media platforms can create user profiles that record your preferences and interests. This enables interest-based advertising to be displayed to you both on and off the respective social media platform. If you have an account with the relevant social network, interest-based advertising may be displayed on all devices on which you are currently logged in or have previously been logged in.
Please also note that we are not able to track all data processing activities on social media platforms. Depending on the provider, further processing operations may therefore be carried out by the operators of the social media platforms. For further details, please refer to the terms of use and privacy policies of the respective social media platforms.
Legal basis
Our social media accounts are intended to ensure the most comprehensive online presence possible. This constitutes a legitimate interest within the meaning of Article 6(1)(f) of the GDPR. The analytics processes initiated by the social media platforms may be based on different legal grounds, which must be specified by the operators of those platforms (e.g. consent within the meaning of Article 6(1)(a) of the GDPR).
Data controller and exercising your rights
When you visit one of our social media pages (e.g. Facebook), we are jointly responsible with the operator of the social media platform for the data processing operations triggered by that visit. You may, in principle, exercise your rights (right of access, rectification, erasure, restriction of processing, data portability and the right to lodge a complaint) both against us and against the operator of the relevant social media platform (e.g. against Facebook).
Please note that, despite our joint responsibility with the social media platform operators, we do not have full control over the data processing operations carried out by the social media platforms. Our options depend largely on the corporate policy of the respective provider.
Retention period
Data collected directly by us via our social media presence will be deleted from our systems as soon as you request its deletion, withdraw your consent to its storage, or the purpose for storing the data no longer applies. Stored cookies remain on your device until you delete them. Mandatory legal provisions – in particular retention periods – remain unaffected.
We have no influence over the retention period of your data stored by the operators of social networks for their own purposes. For further details, please contact the operators of the social networks directly (e.g. in their privacy policy, see below).
Your rights
You have the right at any time to obtain, free of charge, information about the source, recipients and purpose of your stored personal data. You also have the right to object, the right to data portability and the right to lodge a complaint with the relevant supervisory authority. Furthermore, you may request the rectification, restriction, erasure and, under certain circumstances, the restriction of the processing of your personal data.
Social networks in detail
We have a profile on Facebook. The provider of this service is Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland (hereinafter ‘Meta’). According to Meta, the data collected is also transferred to the USA and other third countries.
We have entered into a joint processing agreement (Controller Addendum) with Meta. This agreement sets out which data processing operations we and Meta are responsible for when you visit our Facebook page. You can view this agreement via the following link: www.facebook.com/legal/terms/page_controller_addendum.
You can adjust your advertising settings yourself in your user account. To do so, click on the following link and log in: www.facebook.com/settings.
The transfer of data to the USA is based on the EU Commission’s Standard Contractual Clauses. Further details can be found here: www.facebook.com/legal/EU_data_transfer_addendum and de-de.facebook.com/help/566994660333381.
For further details, please refer to Facebook’s Privacy Policy: www.facebook.com/about/privacy/.
The company is certified under the ‘EU-US Data Privacy Framework’ (DPF). The DPF is an agreement between the European Union and the US designed to ensure compliance with European data protection standards when data is processed in the US. Every company certified under the DPF undertakes to comply with these data protection standards. Further information on this is available from the provider via the following link: www.dataprivacyframework.gov/s/participant-search/participant-detail
We have an Instagram profile. The provider of this service is Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland.
Data transfers to the USA are based on the European Commission’s Standard Contractual Clauses. Further details can be found here: www.facebook.com/legal/EU_data_transfer_addendum, privacycenter.instagram.com/policy/ and de-de.facebook.com/help/566994660333381.
For details on how Instagram handles your personal data, please refer to Instagram’s Privacy Policy: privacycenter.instagram.com/policy/.
The company is certified under the ‘EU-US Data Privacy Framework’ (DPF). The DPF is an agreement between the European Union and the USA designed to ensure compliance with European data protection standards when data is processed in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. Further information on this is available from the provider via the following link: www.dataprivacyframework.gov/s/participant-search/participant-detail
We have a profile on LinkedIn. The provider is LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland. LinkedIn uses advertising cookies.
If you wish to disable LinkedIn advertising cookies, please use the following link: www.linkedin.com/psettings/guest-controls/retargeting-opt-out.
Data transfers to the USA are based on the EU Commission’s Standard Contractual Clauses. Further details can be found here: www.linkedin.com/legal/l/dpa and www.linkedin.com/legal/l/eu-sccs.
For details on how LinkedIn handles your personal data, please refer to LinkedIn’s privacy policy: www.linkedin.com/legal/privacy-policy.
We have a profile on XING. The provider is New Work SE, Dammtorstraße 30, 20354 Hamburg, Germany. For details on how they handle your personal data, please refer to XING’s privacy policy: privacy.xing.com/de/datenschutzerklaerung.
Youtube
We have a profile on YouTube. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. For details on how they handle your personal data, please refer to YouTube’s privacy policy: policies.google.com/privacy.
The company is certified under the ‘EU-US Data Privacy Framework’ (DPF). The DPF is an agreement between the European Union and the USA designed to ensure compliance with European data protection standards when data is processed in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. Further information on this is available from the provider via the following link: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt000000001L5AAI&status=Active
YouTube with enhanced data protection
This website embeds videos from YouTube. When you visit one of the pages on this website that features embedded YouTube content, a connection is established with YouTube’s servers. In doing so, the YouTube server is informed which of our pages you have visited. If you are logged into your YouTube account, you allow YouTube to link your browsing behaviour directly to your personal profile. You can prevent this by logging out of your YouTube account.
We use YouTube in enhanced privacy mode. According to YouTube, videos played in enhanced privacy mode are not used to personalise your browsing experience on YouTube. Advertisements displayed in enhanced privacy mode are also not personalised. No cookies are set in enhanced privacy mode. Instead, however, so-called local storage elements are stored in the user’s browser; these contain personal data in a similar way to cookies and can be used for recognition purposes. Details on enhanced privacy mode can be found here: https://support.google.com/youtube/answer/171780.
Where applicable, further data processing operations may be triggered following the activation of a YouTube video, over which we have no control.
The use of YouTube is in the interests of presenting our online services in an appealing manner. This constitutes a legitimate interest within the meaning of Article 6(1)(f) of the GDPR. Where consent has been sought, processing takes place exclusively on the basis of Article 6(1)(a) of the GDPR and Section 25(1) of the TDDDG, insofar as the consent covers the storage of cookies or access to information on the user’s device (e.g. device fingerprinting) within the meaning of the TDDDG. Consent may be withdrawn at any time.
Further information on data protection at YouTube can be found in their privacy policy at: policies.google.com/privacy.
Blogs and publication platforms
We use blogs or similar means of online communication and publication (hereinafter referred to as ‘publication platforms’). Readers’ data is processed for the purposes of the publication platform only to the extent necessary for its presentation and for communication between authors and readers, or for security reasons. For further details, please refer to the information on the processing of visitors to our publication medium set out in this privacy notice.
Comments and posts: When users leave comments or other posts, their IP addresses may be stored on the basis of our legitimate interests. This is done for our own protection in the event that someone posts unlawful content in comments or contributions (insults, prohibited political propaganda, etc.). In such cases, we ourselves may be held liable for the comment or contribution and are therefore interested in the author’s identity.
Furthermore, we reserve the right, on the basis of our legitimate interests, to process users’ data for the purpose of spam detection.
On the same legal basis, we reserve the right, in the case of surveys, to store users’ IP addresses for the duration of the survey and to use cookies to prevent multiple votes.
Personal information provided in comments and posts, including any contact details and website information, as well as the content of such posts, will be stored permanently by us until the user objects.
- Types of data processed: Personal details (e.g. names, addresses), contact details (e.g. email addresses, telephone numbers), content data (e.g. text entries, photographs, videos), usage data (e.g. websites visited, interest in content, access times), meta/communication data (e.g. device information, IP addresses).
- Data subjects: Users (e.g. website visitors, users of online services).
- Purposes of processing: Contractual performance and services, feedback (e.g. collecting feedback via online forms), security measures, administration and responding to enquiries.
Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6(1), first sentence, point (b) of the GDPR), legitimate interests (Article 6(1), first sentence, point (f) of the GDPR), consent (Article 6(1), first sentence, point (a) of the GDPR), protection of vital interests (Article 6(1), first sentence, point (d) of the GDPR).
Contacting Us
When you contact us – for example, via the contact form, by email, telephone or social media – we process the data you provide to the extent necessary to handle and respond to your enquiry.
If the enquiry is made in the context of an existing or prospective contractual relationship, the legal basis is Article 6(1)(b) of the GDPR. In all other cases, we base the processing on our legitimate interest in handling and responding to enquiries addressed to us, in accordance with Article 6(1)(f) of the GDPR.
Whistleblowing Scheme
Any person with a business connection to our company may report a breach or wrongdoing via our whistleblowing scheme. In doing so, we are complying with the provisions of the Whistleblower Protection Act (HinSchG). Reports may be made in person, by post or by email.
The purpose of processing is to receive and investigate breaches of rules, to prevent future misconduct, to assert or defend legal claims, to exonerate employees who have been wrongly accused, and to fulfil our compliance obligations.
The data processed includes details of the person making the report and of the individuals whose conduct is the subject of the report, in particular their names, contact details, positions and the specific details of the reported incident. Access is restricted exclusively to those persons entrusted with handling the report; all parties involved are bound by a duty of confidentiality. Data will only be disclosed to third parties to the extent that we are legally obliged to assist in the investigation of criminal offences.
The data will be erased as soon as it is no longer required for the investigation and final assessment of the matter, in accordance with Article 17 of the GDPR, provided that there are no statutory retention periods or legitimate interests that preclude this.
The legal bases are Article 6(1)(c) of the GDPR in conjunction with Section 13 of the HinSchG (fulfilment of our statutory compliance obligations), Article 6(1)(f) of the GDPR (legitimate interest in investigating misconduct) and, where the whistleblower is personally affected, Article 6(1)(a) of the GDPR. No automated individual decision-making or profiling within the meaning of Article 22 of the GDPR takes place.
Video conferences, online meetings and webinars
We use third-party platforms for video and audio conferences, webinars and similar formats. In this context, registration and contact details, video and audio content, as well as chat messages and shared screen content, are processed on the third-party providers’ servers. Where we ask for your consent, for example to record a conversation, the legal basis is Article 6(1)(a) of the GDPR. Furthermore, the use of these platforms may form part of our (pre-)contractual services (Article 6(1)(b) of the GDPR) or be based on our legitimate interest in efficient and secure communication (Article 6(1)(f) of the GDPR). Please also refer to the privacy policy of the relevant third-party provider.
Newsletter via Brevo (formerly Sendinblue)
With your consent, you can subscribe to our newsletter, through which we will keep you informed about topics relating to our company, as well as our services and offers. The newsletter is for promotional and informational purposes.
We use the double opt-in procedure for subscribing to our newsletter. This means that, following your registration, we will send an email to the address you provided, asking you to confirm that you wish to receive the newsletter. If you do not confirm your registration within 24 hours, your details will be blocked and automatically deleted after one month. In addition, we store the IP addresses you use and the times of your registration and confirmation. The purpose of this procedure is to verify your registration and, if necessary, to investigate any potential misuse of your personal data.
Your name and email address are required in order to receive the newsletter. Following your confirmation, we will store your email address and name for the purpose of sending you the newsletter and addressing you personally.
The legal basis for sending the newsletter is your consent pursuant to Article 6(1)(a) of the GDPR in conjunction with Article 7 of the GDPR. Your consent also covers the analysis of usage behaviour and the creation of recipient segments, as described below. Insofar as information is read from or stored on your device for the purpose of measuring performance, we also base this on your consent in accordance with Section 25(1) of the German Telemedia Act (TDDDG).
You may withdraw your consent to receive the newsletter at any time and unsubscribe from it. You may withdraw your consent by clicking on the link provided in every newsletter email or by sending a message to the contact details given in the legal notice. The legal basis is your consent within the meaning of Article 6(1)(a) of the GDPR. We use Brevo (formerly Sendinblue) as our service provider: Sendinblue GmbH (trading as Brevo), Köpenicker Str. 126, 10179 Berlin, which acts as a certified data processor bound by our instructions.
With the help of Brevo, we are able to analyse our newsletter campaigns. This allows us, for example, to see whether a newsletter message has been opened and which links, if any, have been clicked. In this way, we can determine, amongst other things, which links have been clicked particularly frequently.
We can also see whether certain predefined actions were carried out after the newsletter was opened or clicked on (conversion rate). For example, we can see whether you made a purchase after clicking on a link in the newsletter.
Brevo also enables us to categorise newsletter recipients into different groups (‘cluster’ them). For example, newsletter recipients can be categorised by age, gender or place of residence. This enables us to tailor the newsletters more effectively to the respective target groups.
You may withdraw your consent to receive the newsletter and to the aforementioned analysis at any time with future effect, and unsubscribe from the newsletter. You can withdraw your consent by clicking on the unsubscribe link provided in every newsletter email or by sending a message to the contact details given in the legal notice. Unsubscribing is just as easy as subscribing.
For detailed information on Brevo’s functions, please refer to the following link: www.brevo.com/de/newsletter-software/.
The data you have provided to us for the purpose of receiving the newsletter will be stored by us or the newsletter service provider until you unsubscribe from the newsletter, and will be deleted from the newsletter distribution list once you have unsubscribed. Data stored by us for other purposes remains unaffected by this.
Once you have unsubscribed from the newsletter mailing list, your email address may be stored on a blacklist by us or the newsletter service provider, where necessary to prevent future mailings. The data from the blacklist is used solely for this purpose and is not combined with any other data. This serves both your interests and our interest in complying with legal requirements when sending newsletters (legitimate interest within the meaning of Article 6(1)(f) of the GDPR). There is no time limit on storage on the blacklist. You may object to this storage provided that your interests override our legitimate interest.
For further details, please refer to Brevo’s privacy policy at: www.brevo.com/de/datenschutz-uebersicht/ and https://www.brevo.com/de/legal/privacypolicy/.
Marketing communications via email, post, fax or telephone
We process marketing communications sent by post on the basis of our legitimate interest, Article 6(1)(f) of the GDPR. Advertising by email, telephone or fax generally requires your prior consent, Article 6(1)(a) of the GDPR in conjunction with Section 7 of the German Unfair Competition Act (UWG); this applies irrespective of the legal basis under the GDPR. An exception applies to email advertising to existing customers for our own similar goods or services, subject to the strict conditions set out in Section 7(3) of the UWG.
You may withdraw any consent you have given at any time or object to promotional communications at any time. Following withdrawal or objection, we will retain the data required for evidence purposes on the basis of our legitimate interest for up to three years, limited to the purpose of defending against claims.
Deletion of data
We delete personal data in accordance with legal requirements as soon as the underlying consent is withdrawn or the purpose of processing no longer applies. If deletion is precluded for other legally permissible purposes, such as retention obligations under commercial or tax law, we restrict processing to those purposes.
Your rights as a data subject
Under the GDPR, you have the following rights:
- Withdrawal of consent with effect for the future (Article 7(3) of the GDPR)
- Access to the data we process and the information specified in Article 15 of the GDPR
- Rectification of inaccurate data and completion of incomplete data (Article 16 of the GDPR)
- Erasure of your data subject to the conditions set out in Article 17 of the GDPR (‘right to be forgotten’)
- Restriction of processing in accordance with the conditions set out in Article 18 of the GDPR
- Data portability in accordance with the conditions set out in Article 20 of the GDPR
- Objection to processing based on Article 6(1)(e) or (f) of the GDPR, as well as to direct marketing (Article 21 of the GDPR)
- Lodging a complaint with a data protection supervisory authority (Article 77 of the GDPR)
- Effective judicial remedy (Article 79 of the GDPR)
To exercise these rights, please contact the data controller or the data protection officer using the contact details provided above.
Definitions
Personal data means any information relating to an identified or identifiable natural person. Processing means any operation or set of operations which is carried out on personal data, whether or not by automated means, such as collection, storage, alteration or erasure. The controller is the body that determines the purposes and means of the processing; a processor processes data on the controller’s behalf. Consent is any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which they signify their agreement to the processing (Article 4 of the GDPR).
Children and young people
Our services are aimed at adults. We ask that anyone under the age of 18 does not provide us with any personal data without the consent of their parents or legal guardians.
Application process
Privacy Notice for Job Applicants
We are delighted that you are interested in working with us. Below, we provide information on how we process your personal data during the application process.
We process the data provided in connection with your application in order to assess your suitability for the advertised position and, where applicable, for other vacant roles, and to carry out the application process.
The legal basis is primarily Article 6(1)(b) of the GDPR. If, following the conclusion of the process, processing is necessary to assert or defend legal claims, we rely on our legitimate interest under Article 6(1)(f) of the GDPR. Where we process special categories of personal data within the meaning of Article 9 of the GDPR, such as health data relating to a severe disability, we rely on Article 9(2)(b) of the GDPR in conjunction with Section 26(3) of the Federal Data Protection Act (BDSG).
We delete the data of unsuccessful applicants after six months. If you have consented to your data being retained in the applicant pool, we will delete your data after two years. If you are offered a position, we will transfer your data to our HR information system.
Your application will first be reviewed by the HR department and, if suitable, forwarded internally to the relevant line managers. Access to your data is restricted to those who require it for the proper conduct of the recruitment process.
Privacy Notice for the rexx Applicant Portal
We use the rexx Suite from rexx systems GmbH as a data processor acting in accordance with our instructions for the technical provision of our online applicant portal and the administration of the application process. Data transmitted via the applicant portal – in particular contact details, application documents, information on qualifications, as well as communication and the status of the application process – is processed by rexx exclusively on our behalf and only to the extent necessary for the provision of the portal, the processing of your application and the conduct of the application process.
At BHI, access to applicants’ data is restricted to those persons who require it for the purposes of the recruitment process, in particular the Human Resources department and the relevant line managers. The legal basis is Article 6(1)(b) of the GDPR. Where storage is necessary after the conclusion of the process to defend against or enforce legal claims, this is carried out on the basis of Article 6(1)(f) of the GDPR. The retention periods mentioned above apply accordingly.
Where applicants consent to being included in the applicant pool, further storage takes place on the basis of Article 6(1)(a) of the GDPR. Consent may be withdrawn at any time with effect for the future.
WhatsApp in the application process
As part of the application process, we also use the WhatsApp messaging service provided by WhatsApp Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland (part of the Meta group of companies), to simplify communication during the application process. We have no influence over the nature and scope of the data processed by WhatsApp itself (including, amongst other things, registration, usage, connection and device data); further information on this can be found at www.whatsapp.com/legal/privacy-policy.
Before you contact us via WhatsApp, we would like to draw your attention to this processing. If you use WhatsApp to contact us, we will process the data transmitted in the process (telephone number, profile name, message content and, where applicable, attachments such as your CV or certificates) for the purpose of processing your application. The legal basis is your consent, Article 6(1)(a) of the GDPR, which you give by actively contacting us whilst being aware of this notice.
Your data will be stored for the duration of the application process and deleted once it has been completed, unless you consent to it being stored for a longer period.