Transparency Statement for Employees (m/f/d)
Data subjects
This statement is directed at all persons who are employees of the controller, including applicants and former employees. All references to persons refer to all genders and the associated linguistic forms, in particular diverse, female, male. Every reference to a person is to be understood with the addition "(m/f/d)".
Controller
The controller for the processing described here is: Adbaker GmbH, Kalscheurener Str. 19A, 50354 Hürth, mail@adbaker.de, T: +49 (0) 221 99983680, e-mail: mail@adbaker.de, represented by the managing director Simon Mader.
Rights of the data subjects and other notices
(1) With regard to the data stored about their person, data subjects have the following rights: the right of access, the right to rectification of inaccurate data, the right to erasure of data for which there is no longer any reason for retention, the right to restriction of processing, and the right to data portability. Furthermore, they have the right to lodge a complaint with the supervisory authority responsible for the controller.
(2) Insofar as the processing is based on the consent of the data subjects, the data subjects may revoke their consent at any time with effect for the future; for example, by informal message to one of the above-mentioned contact channels (Controller).
(3) Insofar as the processing is based on the pursuit of a legitimate interest, i.e. on Article 6 (1) sentence 1 lit. f GDPR, the data subjects may object to the processing at any time; for example, by informal message to one of the above-mentioned contact channels (Controller). If the objection is justified, the processing will be terminated. If the legitimate interest lies in direct marketing, the objection is always justified.
(4) Automated decision-making, including profiling, does not take place.
(5) A legal obligation to process exists only insofar as reference is made below to Article 6 (1) sentence 1 lit. c GDPR.
Data processing
(1) In the application procedure, the application data is received and reviewed. In the event of continued interest, this is followed by a job interview, whereby data is collected, stored, and used to arrange the appointment. In the event of continuing interest, the controller submits an offer for an employment relationship. In each of the aforementioned processing steps, it is also possible that a rejection occurs. The purpose of the aforementioned processing operations is the conduct of the application procedure. The legal basis is Article 88 GDPR in conjunction with § 26 (1) BDSG 2018 (German Federal Data Protection Act).
(2) In the employment relationship, all access and/or communication data in connection with the fulfillment of the employment contract (e.g. e-mails) is processed. The purpose of the aforementioned processing operations is the implementation of the employment relationship. The legal basis is Article 88 GDPR in conjunction with § 26 (1) BDSG 2018. In addition, the following data is processed to fulfill statutory obligations: data relevant for taxation (§ 147 AO, § 257 HGB), health insurance / sick note data (§ 198 SGB V, § 165 SGB VII), payroll account data (§ 41 EStG), working time data (§ 17 MiLoG, § 16 ArbG). The purpose is the fulfillment of the legal obligations stated in the references in parentheses. The legal basis is then Article 6 (1) sentence 1 lit. c GDPR.
(3) In the event of a rejection in the application procedure, the employment relationship ends with the rejection. In all other cases, the employment relationship ends through termination, mutual agreement, or retirement. In any case, the following applies: after the employment relationship, the data is initially retained as follows:
- Data relevant for the taxation of the controller is generally retained for six years. By way of exception, payroll lists (including special payments) and employee insurance records are retained for ten years. The respective period begins in the year in which the last entry was made in the book, the inventory, the opening balance sheet, the annual financial statements, or the management report was prepared, the commercial or business letter was received or sent, or the accounting voucher was created, or the record was made, or the other documents were created (§ 147 AO).
- Health insurer data and sick note data are retained for at least five years (§ 198 SGB V, § 165 SGB VII).
- Data arising from the documentation of working hours within the meaning of § 17 MiLoG and § 16 ArbZG is stored for two years (§ 17 MiLoG and § 16 ArbZG).
- Payroll account data is stored until the end of the sixth calendar year following the last recorded wage payment (§ 41 EStG).
- If the processing of the data is based on consent, the data
- that is the subject of the consent is retained until the consent is revoked or until the purpose associated with its processing lapses.
- that proves that consent was given is retained for three years, whereby this period begins on December 31 of the calendar year in which either the consent is revoked or the data is deleted for other reasons (Article 7 (1) GDPR).
- In the event of a rejection in the application procedure, the application data is retained for six months, whereby this period begins at the time of the rejection.
In the cases of numbers 1 to 4 and 5b, the processing serves the fulfillment of the legal obligations stated in the references in parentheses, whereby Article 6 (1) sentence 1 lit. c GDPR is the legal basis. In the case of number 4a, the purpose is communicated separately, whereby Article 88 GDPR in conjunction with § 26 (2) BDSG 2018 is the legal basis. In the case of number 5, the processing serves the defense against claims under anti-discrimination law, whereby Article 6 (1) sentence 1 lit. f GDPR is the legal basis.
(4) In addition to the above-mentioned processing operations, the following also takes place:
- In addition to paragraph 1, there is the possibility that, in the event of a rejection, the controller asks the applicant to consent to being included in an applicant pool. Then there is the possibility that the controller informs the employee about future, possible employment relationships. The purpose is to create the possibility of staying in contact with the applicant. The legal basis is solely consent within the meaning of Article 88 GDPR in conjunction with § 26 (2) BDSG 2018.
- In all of the aforementioned phases of processing, there is the possibility that the controller offers the data subjects the option of communicating with it via video conference. The legal basis is solely consent within the meaning of Article 88 GDPR in conjunction with § 26 (2) BDSG 2018. This consent then covers both the processing of data pursuant to Article 9 (1) GDPR (e.g. glasses, religious symbols) and the use of the video conferencing tool.
- In all of the aforementioned phases of processing, there is the possibility that the controller offers the data subjects the option of having film, photo, and/or sound recordings of them made for the purpose of company presentation. The legal basis is solely consent within the meaning of Article 88 GDPR in conjunction with § 26 (2) BDSG 2018. This consent then covers both the processing of data pursuant to Article 9 (1) GDPR (e.g. glasses, religious symbols) and the places of publication specified in more detail in the consent text.
(5) In the context of the data processing described above, the following are used:
- An external tax consultancy firm is entrusted with the payroll accounting. Insofar as data is processed there, this does not constitute processing on behalf (cf. DSK Short Paper 13), but a data transfer, which in turn is justified by Article 6 (1) sentence 1 lit. f GDPR.
- The cloud tool "Google Workspace" and the downstream tool "Google Docs" of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4 (Ireland) are used, whereby data traffic with Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043 (USA) cannot be ruled out. The provider was commissioned pursuant to Article 28 GDPR. The use of this third-party provider is not precluded by the fact that it is based outside the EU. For the provider has committed itself in accordance with the EU Standard Contractual Clauses.
- The project management tool "Asana" of Aana Inc., 1550 Bryant St #200, San Francisco, CA 94103, 6399 (USA) is used. The use of this third-party provider is not precluded by the fact that it is based outside the EU. For the provider has committed itself in accordance with the EU Standard Contractual Clauses.
- The CRM tool "HubSpot" of HubSpot, Inc. (USA) is used, which was commissioned pursuant to Article 28 GDPR. The use of this third-party provider is not precluded by the fact that it is based outside the EU. For the provider has committed itself in accordance with the EU Standard Contractual Clauses.
- In connection with automation, the interface tool "Zapier" of Zapier, Inc. (USA) is used, which was commissioned pursuant to Article 28 GDPR. Further details on the manner of processing by this third-party provider are described here: https://zapier.com/how-it-works. In short: With Zapier, the controller can connect applications so that customer and prospect data can be exchanged automatically between the various applications. The processing is not precluded by the fact that the provider is based outside the European Union. For the provider has committed itself in accordance with the EU Standard Contractual Clauses.
- The accounting tool "Lexoffice" of Haufe-Lexware GmbH & Co. KG, Munzinger Straße 9, 79111 Freiburg (Germany) is used. The provider was commissioned pursuant to Article 28 GDPR.
- The customer service tool "Zendesk" of Zendesk, Inc. (USA) is used, which was commissioned pursuant to Article 28 GDPR. The processing is not precluded by the fact that the provider is based outside the European Union. For the provider has committed itself in accordance with the EU Standard Contractual Clauses.
- The video communication tool "Loom" of Loom, Inc. (USA) is used, which was commissioned pursuant to Article 28 GDPR. The processing is not precluded by the fact that the provider is based outside the European Union. For the provider has committed itself in accordance with the EU Standard Contractual Clauses.
- The project management tool "Slack" of Slack Technologies Limited (Ireland – EU) is used, which was commissioned pursuant to Article 28 GDPR. The processing is not precluded by the fact that it cannot be ruled out that Slack Technologies Inc. (USA) obtains access to the data. For it has committed itself in accordance with the EU Standard Contractual Clauses.
- The online fax and telephone service sipgate of sipgate GmbH (Germany) is used, in that fax messages are received and sent there in the context of contract-related communication.
- The feedback tool "Leapsome" of Leapsome GmbH (Germany) is used.
- The platform tool "KAJABI" of Kajabi LLC (USA) is used, which was commissioned pursuant to Article 28 GDPR. The processing is not precluded by the fact that the provider is based outside the European Union. For the provider has committed itself in accordance with the EU Standard Contractual Clauses.
- The recruiting service provider Nadja Czapran (Germany) is used.
- The onboarding tool "Notion" of 2022 Notion Labs, Inc. (USA) is used, which was commissioned pursuant to Article 28 GDPR. The processing is not precluded by the fact that the provider is based outside the European Union. For the provider has committed itself in accordance with the EU Standard Contractual Clauses.
- The recruiting tool "Personio - Recruiting" of Personio GmbH (Germany - EU) is used, which was commissioned pursuant to Article 28 GDPR. Further details on the manner of processing by this third-party provider are described here: https://www.personio.de (there under the tab "Funktionen" / features).
- For conducting video chats, Zoom of Zoom Video Communications, Inc. (USA) is used, which was commissioned pursuant to Article 28 GDPR. The processing is not precluded by the fact that the provider is based outside the European Union. For the provider has committed itself in accordance with the EU Standard Contractual Clauses.
- The chat software "Miro" of RealtimeBord, Inc. (USA) is used, which was commissioned pursuant to Article 28 GDPR. The processing is not precluded by the fact that the provider is based outside the European Union. For the provider has committed itself in accordance with the EU Standard Contractual Clauses.