Privacy Statement for Business Contacts
(Customers, Clients, interested parties, suppliers)
Foreword
At Brauns INTERNATION Moving Services GmbH we value your privacy and want you to know how your information will be handled and used. This Privacy Statement applies to inform you about the categories of personal data, the purpose of data processing and who has access to your personal data in the case of doing business together.
Responsible Controller
Brauns INTERNATIONAL Moving Services GmbH
Washingtonstr. 3
27580 Bremerhaven
Germany
Tel.:+49.471.98200.0
Fax: +49.471.98200.98
mail@brauns-international.de
Data Protection Officer
Ingenieurbüro Derschewsky GbR – Nicolas Derschewsky
Alpenrosenweg 4
26203 Wardenburg
Germany
Mail: datenschutz@ib-derschewsky.de
Purposes, legal bases and recipients
Address management
Purpose: Complete ERP processing to fulfill business purposes regarding customers, prospects and suppliers. Basis for further processing of operational purposes, e.g. creation of orders, purchase orders, invoices
Description: Save company data to record purchase orders, orders, invoices, goods receipts
Categories of (personal) data: Personal details,Address details
Special categories of personal data: no
Legal bases: Art. 6 GDPR para. 1 lit. b,Art. 6 GDPR para. 1 lit. f
Justification of a legitimate interest: Centralization for effective communication and customer relationship management, support for sales and marketing
Categories of internal recipients: Employees
Transfer to a third country: no
Time limits for erasure: Until the data is no longer current or required, then check and delete if necessary
General processing of payment transactions
Purpose: General processing of payments, liquidity planning
Description: Manually initiated payment procedure in the financial accounting system
Categories of (personal) data: personal details, bank details
Special categories of personal data: no
Legal bases: Art. 6 GDPR para. 1 lit. b
Categories of internal recipients: Financial accounting department
Transfer to a third country: possible
Time limits for erasure: Retention for 10 years in accordance with commercial and tax regulations.
Submission of offers
Purpose: Submission of offers
Description: Storage of inquiries, quotations and evaluation of customers based on financial values such as turnover and analog file management
Categories of (personal) data: Personal details, Address details, Details of the goods to be moved
Special categories of personal data: no
Legal bases: Art. 6 GDPR para. 1 lit. b
Categories of internal recipients: Employees
Categories of external recipients: interested parties, customers, clients
Transfer to a third country: no
Time limits for erasure: Retention for 10 years in accordance with commercial and tax regulations.
Creation of files
Purpose: Recording and processing data for customer service and maintenance
Description: Preparation of analog and digital folders (folder structure)
Categories of (personal) data: Personal details, Address details, Master data
Special categories of personal data: Possible
Legal bases: Art. 6 GDPR para. 1 lit. b
Categories of internal recipients: accounting
Transfer to a third country: no
Time limits for erasure: Retention for 10 years in accordance with commercial and tax regulations.
Archiving the data
Purpose: Optical archive for audit-proof archiving of order and financial accounting data. Business documents such as vendor invoices or documents are manually scanned and archived here.
Digital storage of all order-related documents in the order database
Description: Archiving of all order-related data, documents such as drawings, orders, correspondence, invoices, appointments
Categories of (personal) data: Personal details, Contract data, Address details, Bank details, Data for social insurance, Qualification data, Master data, Delivery data, Billing data, Payment data
Special categories of personal data: no
Legal bases: Art. 6 GDPR para. 1 lit. c, §257 HGB; §147 AO
Categories of internal recipients: authorized employees
Transfer to a third country: no
Time limits for erasure: Retention for 10 years in accordance with commercial and tax regulations.
Audit
Purpose: Internal audits for the continuous monitoring of processes to ensure compliance with legal standards within the company.
Description: Carrying out internal audits
Categories of (personal) data: Personal details, Contract data, Master data, Billing data
Special categories of personal data: no
Legal bases: Art. 6 GDPR para. 1 lit. f
Justification of a legitimate interest: Implementation to review and comply with internal and external standards, improve processes and compliance
Categories of internal recipients: Management
Transfer to a third country: no
Time limits for erasure: 5-10 years, depending on the requirements of the examination authorities
Order management
Purpose: Management of order contents
Description: Saving the order data, executing the orders
Categories of (personal) data: Personal details, Address details, Bank details, Master data, Authority data, ID data, Details of the goods to be moved
Special categories of personal data: no
Legal bases: Art. 6 GDPR para. 1 lit. a,Art. 6 GDPR para. 1 lit. b
Categories of internal recipients: Management, Employees
Categories of external recipients: Freight forwarders, shipping companies, relocation service providers, customs agents
Transfer to a third country: no
Time limits for erasure: Retention for 10 years in accordance with commercial and tax regulations.
Disposition requests
Purpose: Used for contract fulfillment
Description: Basis for processing the orders
Categories of (personal) data: Personal details, Address details, Details of the goods to be moved
Special categories of personal data: no
Legal bases: Art. 6 GDPR para. 1 lit. b
Categories of internal recipients: Employees
Transfer to a third country: possible
Time limits for erasure: Retention for 10 years in accordance with commercial and tax regulations.
Disposition
Purpose: Planning Ressources
Description: Management of the work processes and assignment of these per cost center / employee
Categories of (personal) data: Personal details, Address details, Details of the goods to be moved
Special categories of personal data: no
Legal bases: Art. 6 GDPR para. 1 lit. b
Categories of internal recipients: Employees
Transfer to a third country: no
Time limits for erasure: Retention for 10 years in accordance with commercial and tax regulations.
Purpose: Provision, processing and archiving of e-mail communication for data backup and efficient process design, as well as scheduling
Description: Receiving, sending and saving emails and email contacts, appointments
Categories of (personal) data: Personal details, Address details, Master data, Usage data
Special categories of personal data: no
Legal bases: Art. 6 GDPR para. 1 lit. b
Categories of internal recipients: IT department
Categories of external recipients: E-mail recipients, appointment participants
Transfer to a third country: no
Time limits for erasure: Business-relevant e-mails 6-10 years
Financial accounting
Purpose: Implementation of financial accounting
Description: Recording of incoming and outgoing invoices with corresponding posting.
Categories of (personal) data: Billing data
Special categories of personal data: no
Legal bases: Art. 6 GDPR para. 1 lit. c, §257 HGB; §147 AO
Categories of internal recipients: Financial accounting department
Categories of external recipients: Tax authorities, tax consultants
Transfer to a third country: possible
Time limits for erasure: Retention for 10 years in accordance with commercial and tax regulations.
IT infrastructure/network administration/IT security
Purpose: Support and administration of the IT infrastructure
Description: Creation, administration, deletion of users, assignment of passwords, installation of software and hardware
Categories of (personal) data: Personal details, Contract data, Address details, Bank details, Data for social insurance, Qualification data, Master data, Insurance data, Billing data, Employee data, Performance data, Usage data, Payment data, ID data
Special categories of personal data: no
Legal bases: Art. 6 GDPR para. 1 lit. c,Art. 6 GDPR para. 1 lit. f, §43 GmbHG
Justification of a legitimate interest: Ensuring operational security, safeguarding data integrity, protection against cyber attacks
Categories of internal recipients: IT department
Categories of external recipients: IT service provider
Transfer to a third country: no
Time limits for erasure: Protocols and reports 6 months to 2 years, depending on security policy.
Maintaining contact via Messenger
Purpose: Internal and external communication
Description: Internal communication with employees, external communication only if the contact originates from the customer
Categories of (personal) data: Personal details, Address details
Special categories of personal data: no
Legal bases: Art. 6 GDPR para. 1 lit. b,Art. 6 GDPR para. 1 lit. f
Justification of a legitimate interest: Enabling fast and efficient communication with business partners and customers, strengthening relationships
Categories of internal recipients: Employees
Categories of external recipients: Messenger service providers, Customers, Suppliers
Transfer to a third country: possible
Time limits for erasure: Depending on content and business relevance 1-3 years
Resource management
Purpose: Optimization of personnel and material deployment for order execution
Description: Planning of personnel and material deployment for order execution
Categories of (personal) data: Personal details, Address details, Details of the goods to be moved
Special categories of personal data: no
Legal bases: Art. 6 GDPR para. 1 lit. b
Categories of internal recipients: Employees
Transfer to a third country: no
Time limits for erasure: Retention for 10 years in accordance with commercial and tax regulations.
Phone / Smartphone / Scanner
Purpose: Communication
Description: Saving the contact details of people for communication
Categories of (personal) data: Personal details, Address details
Special categories of personal data: no
Legal bases: Art. 6 GDPR para. 1 lit. b,Art. 6 GDPR para. 1 lit. f
Justification of a legitimate interest: Providing essential tools for daily communication and document management, increasing productivity
Categories of internal recipients: Employees
Categories of external recipients: Telecommunications providers, Customers, Suppliers
Transfer to a third country: no
Time limits for erasure: Usage data 6 months to 1 year
Relocation orders
Purpose: Used for contract fulfillment
Description: Specifies the processing sequence. To secure the work sequence.
Categories of (personal) data: Personal details, Address details, Details of the goods to be moved
Special categories of personal data: no
Legal bases: Art. 6 GDPR para. 1 lit. b
Categories of internal recipients: Employees, supervisors
Transfer to a third country: possible
Time limits for erasure: Retention for 10 years in accordance with commercial and tax regulations.
Software maintenance
Purpose: Software maintenance to rectify errors, improve performance or other attributes and adapt to changes.
Description: Software maintenance and monitoring
Categories of (personal) data: Personal details, Contract data, Address details, Bank details, Data for social insurance, Qualification data, Master data, Insurance data, Billing data, Employee data, Performance data, Usage data, Payment data, ID data
Special categories of personal data: no
Legal bases: Art. 6 GDPR para. 1 lit. c,Art. 6 GDPR para. 1 lit. f, §43 GmbHG
Justification of a legitimate interest: Ensuring the functionality and security of the systems used, protection against data loss and downtime
Categories of internal recipients: IT depatment
Categories of external recipients: IT service providers
Transfer to a third country: no
Time limits for erasure: Logs and reports after completion of maintenance plus 1-3 years.
Rights of data subjects
You enjoy the following data protection rights vis-à-vis Brauns INTERNATIONAL Moving Services GmbH:
- In accordance with Art. 15 GDPR, you can request information about your personal data processed by the controller.
- You can request rectification in accordance with Art. 16 GDPR if your data are not (or are no longer) correct.
- You can request the erasure of your personal data in accordance with Art. 17 GDPR.
- In accordance with Art. 18 GDPR, you have the right to request a restriction on the processing of your personal data.
- If the requirements of Art. 20(1) GDPR are met, you have the right to receive your data in a structured, commonly used and machine-readable format.
- You have the right to object in accordance with Art. 21 GDPR if the processing of your data is based on a legitimate interest.
- If you have given your consent to a certain type of processing, you can withdraw this consent at any time with effect for the future by informing the relevant contact addresses.
- If you believe that the processing of your personal data violates data protection legislation, you have the right to lodge a complaint with the competent data protection supervisory authority in accordance with Art. 77(1) GDPR.
The competent supervisory authority for Brauns INTERNATIONAL Moving Services GmbH is
Free Hanseatic City of Bremen
The Federal Commissioner for Data Protection and Freedom of Information
Arndtstr. 1
27570 Bremerhaven
Germany
office@datenschutz.bremen.de