Privacy Policy

Who We Are

The controller within the meaning of the General Data Protection Regulation (GDPR) and other data protection regulations is

Kohlbecker Gesamtplan GmbH

Hildastraße 20
76571 Gaggenau
Germany
+49 7225 66 0

www.kohlbecker.de

Contacting the Data Protection Officer

The Data Protection Officer of the controller is:

DataCo GmbH
Nymphenburger Str. 86
80636 München
Germany
+49 89 7400 45840
www.dataguard.de

On this page we inform you about the processing of your personal data on the website.

How we collect and use your personal data depends on how you interact with us or which services you use. We only collect, use or share your personal data when we have a legitimate purpose and legal basis for doing so.

What do we mean by legal basis?

Consent (art. 6 para. 1 clause 1 lit. a GDPR) – You have given us your consent to process your personal data for the specific purpose we have explained to you. You have the right to withdraw your consent at any time. For more information on how you can withdraw your consent, please refer to the subsection “Exercising your rights” in the following sections of this Privacy Policy.

Contract (art. 6 para. 1 clause 1 lit. b GDPR) – We need to use your data to fulfill a contract you have with us. Alternatively, it is necessary to use your data because we have requested it from you or you have taken certain steps yourself before entering into this contract.

Legal obligation (art. 6 para. 1 clause 1 lit. c GDPR) – We must use your data to comply with the law.

Vital interests (art. 6 para. 1 clause 1 lit. d GDPR) – The processing of your data is necessary to protect your vital interests or those of another person— for example, to protect you from serious physical harm.

Public task           
(art. 6 para. 1 clause 1 lit. e GDPR) – The processing of your data is necessary for the performance of a task carried out in the public interest or because it is covered by a task defined by law, e.g. for a statutory function.

Legitimate interests (art. 6 para. 1 clause 1 lit. f GDPR) – The processing of your data is necessary to support a legitimate interest that we or another party have, providing your own interests do not override this.

Please note that we may not be able to provide you with our website services if your data is required to fulfill a contract or legal obligation and you do not provide the requested data.

Data sharing and international transfer

As explained in this Privacy Policy, we use various service providers to help us provide our services and keep your data secure. When we use these service providers, it is necessary for us to share your personal data with them.

We have concluded agreements with all service providers to whom we pass on your data, which oblige them to protect your data.

If your personal data is transferred outside the EU, we will ensure that your personal data receives an equivalent level of protection, either because the country to which your

data is transferred has an “adequate” standard of data protection according to the European Commission, or by applying another safeguard, such as an enhanced contractual arrangement, i.e. the Standard Contractual Clauses (SCCs) adopted by the European Commission.

For example, when we use US service providers, we rely on either the SCCs or the EU-US Data Privacy Framework, depending on the provider. You can request a copy of the SCCs we have entered into with our service providers by sending an email to the email address provided in this Privacy Policy.

Your rights

If your personal data is processed, you are a data subject within the meaning of the GDPR and you have the following rights vis-à-vis the controller:

1. The right to information (Art. 15 GDPR)

You have the right to obtain confirmation from us as to whether or not we are processing your personal data and, if we are, to have access to your personal data and the following information:

  • Processing purposes
  • Categories of personal data
  • Recipients or categories of recipients

The planned storage period or the criteria for determining this period and the existence of the rights to rectification, deletion, restriction or objection

  • Right to lodge a complaint with the competent supervisory authority
  • If applicable, origin of the data (if collected from a third party)
  • If applicable, the existence of automated decision-making, including profiling, and meaningful
  • information about the logic involved, the scope and the expected effects
  • If applicable, transfer of personal data to a third country or international organization

2. Right to rectification (Art. 16 GDPR)

If your personal data is incorrect or incomplete, you have the right to request that the personal data be corrected or completed without undue delay.

3. Right to restriction of processing (Art. 18 GDPR)

If one of the following conditions is met, you have the right to request that the processing of your personal data be restricted:

You contest the accuracy of your personal data, for a period enabling us to verify the accuracy of the personal data.

In the case of unlawful processing, you oppose the deletion of the personal data and request the restriction of its use instead.

We no longer need your personal data for the purposes of the processing, but you require your personal data for the establishment, exercise or defense of legal claims, or

 after you have objected to processing, for the period necessary to verify whether our legitimate grounds override yours.

4. Right to deletion (“right to be forgotten”) (Art. 17 GDPR)

If one of the following reasons applies, you have the right to demand that your personal data be erased without undue delay:

Your data is no longer necessary for the processing purposes for which it was originally collected.

You withdraw your consent and there is no other legal basis for the processing.

You object to the processing and there are no overriding legitimate grounds for the processing or you object to the processing pursuant to Art. 21 para. 2 GDPR.

Your personal data is processed unlawfully.

The deletion is necessary to fulfill a legal obligation under Union law or the law of the member state to which we are subject.

The personal data was collected in relation to information society services offered in accordance with Article 8 para. 1 GDPR.

Please note that the above reasons do not apply if processing is necessary:

For exercising the right of freedom of expression and information;

For compliance with a legal obligation or for the performance of a task carried out in the public interest to which we are subject.

For reasons of public interest in the area of public health.

For archiving purposes in the public interest, scientific or historical research purposes or statistical purposes.

For the establishment, exercise or defense of legal claims.

5. Right to data portability (Art. 20 GDPR)

You have the right to receive your personal data in a structured, commonly used and machine-readable format or to request that it be transmitted to another controller.

6. Right to object to certain data processing (Art. 21 GDPR)

You have the right to object, on grounds relating to your particular situation, at any time, to processing of personal data concerning you which is based on Article 6 para. 1 clause 1 lit. (e) or (f) GDPR. This also applies to profiling based on these provisions.

If the personal data concerning you is processed for direct marketing purposes,

you have the right to object at any time to the processing of your personal data for the purpose

of such advertising; this also applies to profiling insofar as it is associated with such direct advertising.

7. Right to lodge a complaint with a supervisory authority

Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority if you consider that the processing of personal data relating to you infringes the GDPR.

The supervisory authority with which the complaint has been lodged shall inform the complainant of

the status and outcome of the complaint, including the possibility of a judicial remedy pursuant to Art. 78 GDPR.

Provision of the website and creation of log files

1. Description and scope of data processing

Each time our website is accessed, our system automatically collects data and information from the accessing computer’s system.

The following data is collected:

  • Date and time of access
  • Websites from which the user’s system accesses our website
  • Websites that are accessed by the user’s system via our website

This data is stored in the log files of our system.

This data is not stored together with other personal data of the user.

2. Purpose of the data processing

The temporary storage of the IP address by the system is necessary to enable the website to be delivered to the user’s computer. For this purpose, the user’s IP address must remain stored for the duration of the session.

The data is stored in log files to ensure the functionality of the website. We also use the data to optimize the website and to ensure the security of our information technology systems. The data is not analyzed for marketing purposes in this context.

3. Legal basis for data processing

The legal basis for the temporary storage of data and log files is Art. 6 para. 1 clause 1 lit. f

GDPR.

4. Duration of storage

The data will be deleted as soon as it is no longer required to achieve the purpose for which it was collected. In the case of the collection of data for the provision of the website, the data is deleted when the respective session has ended.

If the data is stored in log files, the data is deleted after seven days at the latest. Storage beyond this period is possible. In this case, the IP addresses of the users are deleted or anonymized so that it is no longer possible to identify the accessing client.

5. Exercising your rights

The collection of data for the provision of the website and the storage of data in log files is absolutely necessary for the operation of the website. The user can object to this. Whether the objection is successful must be determined as part of a weighing of interests.

Use of cookies

1. Description and scope of data processing

When you visit our website, we use technical tools for various functions, in particular cookies, which can be stored on your end device. When you access our website and at any time thereafter, you have the choice of whether you generally allow cookies to be set or which individual additional functions you would like to select. You can make changes in your browser settings or via our Consent Manager.

Cookies are text files or information in a database that is stored on your hard disk and assigned to the browser you are using so that certain information can flow to the location that sets the cookie. Below we describe the type of cookies we use:

We use cookies on our website that are not technically necessary. Cookies that are technically non-essential are text files that are not only used for the functionality of the website, but also collect other data.

The following data is processed when technically non-essential cookies are set

  •  IP address

2. Purpose of the data processing

The use of technically non-essential cookies is for the purpose of improving the quality of our website, its content, and thus our reach and efficiency. By setting these cookies, we learn how the website is used and can thus constantly optimize what we offer. In particular, these cookies are used for the following purposes:

  • Google Analytics

3. Legal basis for data processing

The provisions of the Telecommunications and Telemedia Data Protection Act (TTDSG) apply to the storage of information in the end user’s terminal equipment and/or access to information already stored in the end user’s terminal equipment. If the setting and reading

of cookies is technically necessary, this is done to ensure the functionality of our website. In this case, cookies are stored and accessed on your terminal equipment on the basis of Section 25 para. 2 No. 2 TTDSG. This storage and access to the

information in your end device serve to make it easier for you to use our website and to be able to offer you our services as you have requested. Some functions of our website do not work without the use of these cookies and may therefore not be offered. The cookies are generally deleted at the end of the session (e.g. logging out or closing the browser) or after a specified period of time. Information on deviating storage periods for cookies can be found in the following sections of this privacy policy.

Insofar as cookies are used that are technically non-essential, this is done on the basis of your express consent, which you can give via the cookie banner. The basis for the storage and access to information in this case is Section 25 para. 1 TTDSG in conjunction with Art. 6 para. 1 lit. a), Art. 7 GDPR. You can revoke your consent at any time effective for the future visits, or subsequently grant it again by configuring your cookie settings accordingly. Alternatively, you can prevent the storage of cookies by making the appropriate settings in your browser software. Please note that the browser settings you make only apply to the browser you are using. If personal data is processed following the storage of and access to the information on your end device, the provisions of the GDPR apply. Information on this can be found in the following sections of this privacy policy.

Email contact

1. Description and scope of data processing

You can contact us via the email address provided on our website. In this case, the user’s personal data transmitted with the email will be stored.

The data is used exclusively for processing the conversation.

2. Purpose of the data processing

In the case of contact by email, this also constitutes the necessary legitimate interest in the processing of the data.

3. Legal basis for data processing

The legal basis for the processing of data transmitted in the course of sending an email is Art. 6 para. 1 lit. f GDPR. Our legitimate interest is to respond to your request sent by email in the best possible way.

If the email contact is aimed at the conclusion of a contract, the additional legal basis for the processing is Art. 6 para. 1 lit. b GDPR.

4. Duration of storage

The data will be deleted as soon as it is no longer required to achieve the purpose for which it was collected. For personal data sent by email, this is the case when the respective conversation with the user has ended. The conversation is ended when it can be inferred from the circumstances that the matter in question has been conclusively clarified.

The additional personal data collected during the sending process will be deleted after a period of seven days at the latest.

5. Exercising your rights

If the user contacts us by email, they can object to the storage of their personal data at any time. In such a case, the conversation cannot be continued.

All personal data stored in the course of contacting us will be deleted in this case.

Contact form

1. Description and scope of data processing

There is a contact form on our website that can be used for electronic

contact. If a user makes use of this option, the data entered in the input mask will be transmitted to us and stored.

The following data is stored when the message is sent:

  • Email address
  • Surname
  • First name
  • Message
  • IP address of the accessing computer
  • Date and time

2. Purpose of the data processing

The processing of personal data from the input mask of the contact form or via the email address provided serves us solely to process the contact.

The other personal data processed during the sending process is used to prevent misuse of the contact form and to ensure the security of our information technology systems.

3. Legal basis for data processing

The legal basis for the processing of data transmitted in the course of sending an email is Art. 6 para. 1 clause 1 lit. f GDPR. Our legitimate interest is to respond to your inquiry that you send to us via the contact form in the best possible way. If the email contact is aimed at concluding a contract, the additional legal basis for the processing is Art. 6 para. 1 clause 1 lit. b GDPR.

4. Duration of storage

The data will be deleted as soon as it is no longer required to achieve the purpose for which it was collected. For the personal data from the input mask of the contact form and those sent by email, this is the case when the respective conversation with the user has ended. The conversation is ended when it can be inferred from the circumstances that the matter in question has been conclusively clarified.

The additional personal data collected during the sending process will be deleted after a period of seven days at the latest.

5. Exercising your rights

If the user contacts us via the input mask in the contact form, they can object to the storage of their personal data at any time in the following manner:

All personal data stored in the course of contacting us will be deleted in this case.

Application by email and application form

There is an application form on our website that can be used for electronic applications. If an applicant makes use of this option, the data entered in the input mask will be transmitted to us and stored. This data includes

  • Surname
  • First name
  • Curriculum vitae
  • Portfolio

Alternatively, you can also send us your application by email. In this case, we will record your email address and the data you provide in the email.

After sending your application, you will receive an email from us confirming receipt of your application documents.

Your data will not be passed on to third parties. The data will be used exclusively for processing your application.

2. Purpose of the data processing

We process the personal data from the application form solely for the purpose of

processing your application. In the case of contact by email, this also constitutes the necessary legitimate interest in the processing of the data.

The other personal data processed during the sending process serves to prevent misuse of the application form and to ensure the security of our information technology systems.

3. Legal basis for data processing

The legal basis for the processing of your data is the initiation of a contract at the request of the data subject, alternative 1 of Art. 6 para. 1 clause 1 lit. b GDPR and Section 26 para. 1 clause 1 BDSG.

4. Duration of storage

After completion of the application process, the data will be stored for up to 6 months. Your data will be deleted after 6 months at the latest. In the event of a legal obligation, the data will be stored in accordance with the applicable provisions.

The additional personal data collected during the sending process will be deleted after a period of seven days at the latest.

Company websites

Instagram:
Instagram, Part of Meta Platforms Ireland Ltd., 4 Grand Canal Square Grand Canal Harbour, Dublin 2, Ireland

We provide information on our company page and offer Instagram users the opportunity to communicate.

If you carry out an action on our Instagram company page (e.g. comments, posts, likes, etc.), you may make personal data (e.g. real name or photo of your user profile) public.

However, as we generally or largely have no influence on the processing of your personal data by Instagram, we cannot make any binding commitments about the purpose and scope of the processing of your data.

We use our corporate presence on social networks to communicate and exchange information with (potential) customers. In particular, we use the company presence for: Information

The publications on the company website may contain the following content:

  • Information about products
  • Information about services

Every user is free to publish personal data through activities.

Insofar as we process your personal data in order to evaluate your online behavior, offer you competitions or carry out lead campaigns, this is done on the basis of your express declaration of consent, Art. 6 para. 1 clause 1 lit. a, Art. 7 GDPR.

The legal basis for the processing of personal data for the purpose of communicating with customers and interested parties is Art. 6 para. 1 clause 1 lit. f GDPR. Our legitimate interest here is to answer your inquiry in the best possible way or to be able to provide the requested information.

If the contact is aimed at the conclusion of a contract, the additional legal basis for the processing is Art. 6 para. 1 lit. b GDPR.

The data generated by the company website is not stored in our own systems.

For the processing of your personal data in third countries, we have suitable guarantees in the form

of standard data protection clauses under Art. 46 para. 2 lit. c GDPR. A copy of the standard data protection clauses can be requested from us.

You can object to the processing of your personal data that we collect in the context of your use of our corporate presence at any time and assert your rights as a data subject as set out in the “Your rights” section of this privacy policy. To do so, please send us an informal email to *protected email*. You can find more information on the processing of your personal data by Instagram and the corresponding objection options here: Instagram: https://help.instagram.com/519522125107875

YouTube:
YouTube LLC, 901 Cherry Ave., San Bruno, CA 94066, United States

We provide information on our company page and offer YouTube users the opportunity to communicate.

If you carry out an action on our YouTube company page (e.g. comments, contributions, likes, etc.), you may make personal data (e.g. your real name or photo of your user profile) public.

However, as we generally or largely have no influence on the processing of your personal data by YouTube, we cannot make any binding commitments about the purpose and scope of the processing of your data.

We use our corporate presence on social networks to communicate and exchange information with (potential) customers. In particular, we use the company presence for:

  • Information

The publications on the company website may contain the following content:

  • Information about products
  • Information about services

Every user is free to publish personal data through activities.

Insofar as we process your personal data in order to evaluate your online behavior, offer you competitions or carry out lead campaigns, this is done on the basis of your express declaration of consent, Art. 6 para. 1 clause 1 lit. a, Art. 7 GDPR.

The legal basis for the processing of personal data for the purpose of communicating with customers and interested parties is Art. 6 para. 1 clause 1 lit. f GDPR. Our legitimate interest here is to answer your inquiry in the best possible way or to be able to provide the requested information.

If the contact is aimed at the conclusion of a contract, the additional legal basis for the processing is Art. 6 para. 1 lit. b GDPR.

For the processing of your personal data in third countries, we have suitable guarantees in the form

of standard data protection clauses under Art. 46 para. 2 lit. c GDPR. A copy of the standard data protection clauses can be requested from us.

You can object to the processing of your personal data that we collect in the context of your use of our corporate presence at any time and assert your rights as a data subject as set out in the “Your rights” section of this privacy policy. To do so, please send us an informal email to *protected email*. You can find further information on the processing of your personal data by YouTube and the corresponding objection options here: YouTube: https://policies.google.com/privacy?gl=DE&hl=en

Twitter:
Twitter International Company, One Cumberland Place, Fenian Street, Dublin 2, Ireland

We provide information on our company page and offer Twitter users the opportunity to communicate.

If you perform an action on our Twitter company page (e.g. comments, posts, likes, etc.), you may make personal data (e.g. real name or photo of your user profile) public.

However, as we generally or largely have no influence on the processing of your personal data by Twitter, we cannot make any binding commitments about the purpose and scope of the processing of your data.

We use our corporate presence on social networks to communicate and exchange information with (potential) customers. In particular, we use the company presence for: Information

The publications on the company website may contain the following content:

  • Information about products
  • Information about services

Every user is free to publish personal data through activities.

Insofar as we process your personal data in order to evaluate your online behavior, offer you competitions or carry out lead campaigns, this is done on the basis of your express declaration of consent, Art. 6 para. 1 clause 1 lit. a, Art. 7 GDPR.

The legal basis for the processing of personal data for the purpose of communicating with customers and interested parties is Art. 6 para. 1 clause 1 lit. f GDPR. Our legitimate interest here is to answer your inquiry in the best possible way or to be able to provide the requested information.

If the contact is aimed at the conclusion of a contract, the additional legal basis for the processing is Art. 6 para. 1 lit. b GDPR.

The data generated by the company website is not stored in our own systems.

For the processing of your personal data in third countries, we have suitable guarantees in the form

of standard data protection clauses under Art. 46 para. 2 lit. c GDPR. A copy of the standard data protection clauses can be requested from us.

You can object to the processing of your personal data that we collect in the context of your use of our corporate presence at any time and assert your rights as a data subject as set out in the “Your rights” section of this privacy policy. To do so, please send us an informal email to *protected email*. You can find more information on the processing of your personal data by Twitter and the corresponding objection options here:

Twitter: https://twitter.com/de/privacy

Use of company presence in professional networks

1. Scope of data processing

The company website is used for applications, information/PR and active sourcing. We have

no information on the processing of your personal data by the companies jointly responsible for the corporate presence. Further information can be found in the privacy policy of

  • LinkedIn
  • XING

We provide information on our website and offer users the opportunity to communicate.

The company website is used for applications, information/PR and active sourcing.

We have no information on the processing of your personal data by the companies jointly responsible for the company website. Further information can be found in the privacy policy of

LinkedIn:

https://www.linkedin.com/legal/privacy-policy

XING:

https://privacy.xing.com/de

If you carry out an action on our company website (e.g. comments, posts, likes,

etc.), you may make personal data (e.g. real name or photo of your user profile) public.

2. Legal basis for data processing

The legal basis for the processing of personal data for the purpose of communicating with customers and interested parties is Art. 6 para. 1 clause 1 lit. f GDPR. Our legitimate interest here is to answer your inquiry in the best possible way or to be able to provide the requested information.

If the contact is aimed at the conclusion of a contract, the additional legal basis for the processing is Art. 6 para. 1 lit. b GDPR.

3. Purpose of the data processing

The purpose of our company website is to inform users about our services. Every user is free to publish personal data through activities.

4. Duration of storage

The data generated by the company website is not stored in our own systems.

5. Exercising your rights

You can object to the processing of your personal data that we collect in the context of your use of our corporate presence at any time and assert your rights as a data subject as set out in the “Your rights” section of this privacy policy. To do so, please send us an informal email to the email address stated in this privacy policy.

Further information on exercising your rights can be found here:

LinkedIn:

https://www.linkedin.com/legal/privacy-policy

XING:

https://privacy.xing.com/en

Hosting

The website is hosted on servers of a service provider commissioned by us.

Our service provider is:

iS-Fun Internet Services GmbH of the provider iS-Fun Internet Services GmbH. Further information can be found in the provider’s privacy policy: https://www.is-fun.de/datenschutz/

The servers automatically collect and store information in so-called server log files, which your browser automatically transmits when you visit the website. The information stored is

Date and time of access

Websites from which the user’s system accesses our website

Websites that are accessed by the user’s system via our website

This data is not merged with other data sources. This data is collected on the basis of Art. 6 para. 1 lit. f GDPR. Our legitimate interest in processing this data is to display our website without errors and to optimize its functions.

The website server is geographically located in Germany.

Geotargeting

We use the IP address and other information provided by the user (in particular zip code as part of registration or ordering) for regional targeting (so-called “geotargeting”).

Regional targeting is used, for example, to automatically show you regional offers or advertising that is often more relevant to users. The legal basis for the use of the IP address and any other information provided by the user (in particular zip code) is Article 6 para. 1 lit. f GDPR, based on our interest in ensuring a more precise target group approach and thus providing offers and advertising that are more relevant to users.

Part of the IP address and the additional information provided by the user (in particular the zip code) is only read out and not stored separately.

You can prevent geotargeting by using a VPN or proxy server, for example, which prevent precise localization. In addition, depending on the browser you are using, you can also deactivate location localization in the corresponding browser settings (if supported by the respective browser).

We use geotargeting on our website for the following purposes:

  • Advertising purposes

This privacy policy was created with the support of DataGuard.