Privacy Policy

The protection of information related or relating to you, such as your name, your telephone number and your e-mail or IP address (so-called “personal data”) is important to us. Therefore we operate this website and the services offered by us on it in accordance with the applicable data protection laws, in particular the EU data protection basic regulation (“GDPR“) and the Federal Data Protection Act (“FDPA“).

We are delighted to explain how we process your personal data in this regard.

A. Data controller and his data protection officer

I. Name and contact details of the controller

Serafin Unternehmensgruppe GmbH

Löwengrube 18

80333 Munich

Germany

II. Contact details of the data protection officer

Our data protection officer can be reached at the following e-mail address:

datenschutz@serafin-gruppe.de

B. Processing of personal data

I. Accessing the website

Your access to this website requires the processing of your personal data, such as your IP address, date and time of the request, browser type, operating system , time zone difference from GMT, content of the request, access status/HTTP status code. Any further processing of personal data in connection with the use of special services is shown separately below. When you access this website, we process personal data as follows:

a) Purpose of processing

When you access this website, we process your personal data to provide you with this website and to ensure its operation and technical security.

b) Legal basis of the processing

The processing of your personal data when you access this website is based on our legitimate interest in accordance with Art. 6 Para. 1 lit. f GDPR.

Without the processing of personal data, the provision of the website is technically impossible. This also applies to their operation and security. Securing the website also serves your interests.

c) Recipient/recipient categories of your personal data

We disclose your personal data to the following company as a technical service provider:

Domainfactory GmbH

Oskar-Messter-Strasse 33

85737 Ismaning

Germany

d) Storage period of your personal data

We store your personal data for as long as it is necessary for you to access this website.

e) Obligation to provide your personal data

You are not obliged to provide any personal data. However, you will not be able to access this website without your personal data.

f) Cookies

In addition to the aforementioned data, technically necessary and, optionally, technically unnecessary cookies are stored on your computer if you give your consent. Cookies are small text files that are stored on your hard drive in relation to the browser you are using and which provide the party setting the cookie (in this case us) with certain information. They are used to make the website as a whole more user-friendly and effective.

g) TLS encryption

We use TLS encryption to protect your data. You can recognise this by the prefix https:// in the address line of your browser.

h) Conditions for the transfer of personal data to third countries

For the exceptional cases in which personal data is transferred to countries outside the European Economic Area (EEA), i.e. to third countries, this is done under the conditions of Art. 44 et seq. GDPR. We will inform you below about the respective details of the transfer at the relevant points.

The European Commission certifies data protection comparable to the EEA standard in some third countries by means of so-called adequacy decisions. However, in other third countries to which personal data may be transferred, there may not be a consistently high level of data protection due to a lack of legal provisions. If this is the case, we ensure that data protection is sufficiently guaranteed. This is possible through binding company regulations, standard contractual clauses of the European Commission for the protection of personal data in accordance with Art. 46 Para. 1, 2 lit. c GDPR, certificates or recognised codes of conduct.

II. Web analysis with Google Analytics 4.0

We use “Google Analytics” on our website, a web analysis service of Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (“Google”). Google Analytics uses “cookies”, which are text files placed on your device, to help the website analyze how users use the Website. The information generated by a cookie about your use of this website is usually transferred to a Google server in the USA and stored there. By activating IP anonymization, however, Google shortens your IP address within the European Economic Area (European Union and other Member States). Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there.

On our behalf, Google will use this information to analyze your use of the website, to compile reports on website activity and to provide us with other services relating to website and Internet use. The IP address transmitted by your browser in the context of Google Analytics is not linked to other Google data.

You can agree to the storage of cookies by giving the appropriate consent in the cookie consent banner. You can also prevent the collection of data generated by a cookie and relating to your use of the website (including your IP address) and the processing of this data by Google by downloading and installing the browser plug-in available under the following link:

https://tools.google.com/dlpage/gaoptout?hl=en-GB

An opt-out cookie is set which prevents the collection of your data on future visits to this website.

In connection with this service we process your personal data as follows:

a) Purpose of processing

We process your personal data to use Google Analytics.

b) Legal basis of the processing

The processing of your personal data for the use of Google Analytics is based on your consent if you have given the cookie consent in accordance with Art. 6 Para. 1 lit. a GDPR.

c) Recipient of your personal data can be

• Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Irland (as a processor in accordance with Art. 28 GDPR)

• Google LLC, 1600 Amphitheatre Parkway Mountain View, CA 94043, USA

• Alphabet Inc., 1600 Amphitheatre Parkway Mountain View, CA 94043, USA

d) Storage period of your personal data

We store your personal data for as long as necessary for the use of Google Analytics in connection with your respective visit to our website.

e) Third country relation to the processing of your personal data

Google processes your personal data in the USA. For the US, the European Commission issued its adequacy decision on 10 July 2023. It states that the US ensures an adequatelevel of data protection for transfers within this framework. Google LLC is certified under the EU-US Data Privacy Framework and an adequate level of data protection can be assumed.

The processing by Google also takes place within the framework of a contract for order processing.

Further information on Google’s privacy policy can be found here.

f) Obligation to provide your personal data

You are not obliged to disclose personal data.

III. Social media presences

a) LinkedIn

On our website you will find a link to our LinkedIn profile. The operator is LinkedIn Ireland Limited Company, Wilton Place, Dublin 4, Ireland. The website uses the so-called two-click solution. This means that when you visit our site, no personal data is initially passed on to the provider, but only when you click on the marked field. The data mentioned under B. I. of this declaration is transmitted. The legal basis for the use of LinkedIn is your consent in accordance with Art. 6 Para. 1 lit. a) GDPR.

It cannot be ruled out that your data will be transmitted to the parent company of LinkedIn based in the USA. We would like to point out that in this case there is currently no adequate level of protection for the data transfer to the USA. Therefore, we cannot guarantee that LinkedIn can ensure an equivalent level of data protection as we do when processing your data. You can find more information about LinkedIn’s privacy policy here.

b) Xing

On our website you will find a link to our Xing profile. The operator is New Work SE, Dammtorstraße 30, 20354 Hamburg, Germany. The website uses the so-called two-click solution. This means that when you visit our site, no personal data is initially passed on to the provider, but only when you click on the marked field. The data mentioned under B. I. of this declaration. The legal basis for the use of Xing is your consent in accordance with Art. 6 Para. 1 lit. a) GDPR. You can find more information on Xing’s privacy policy here.

C. Your rights as a data subject

You have the right to obtain information about your personal data that we process at any time. If your personal data is incorrect or incomplete, you have the right to rectification and completion. You can request the erasure of your personal data at any time, unless we are legally obliged or entitled to further processing of your data. If the legal requirements are met, you can demand a restriction on the processing of your personal data.

You have the right to object to processing if the data is processed for the purpose of direct marketing or profiling. You can object to processing on the basis of legitimate interests by stating reasons resulting from your particular situation.

If the data is processed on the basis of your consent or within the scope of a contract, you have a right to receive the data provided by you, provided that the rights and freedoms of other persons are not affected.

With regard to the processing of your personal data as described in this data protection declaration, you can exercise the above rights by sending an e-mail to our data protection officer. You can freely revoke your data protection consent at any time with effect for the future; we will point this out in more detail in the context of your consent. Processing carried out before a revocation remains unaffected by the revocation.

You also have the right to lodge a complaint with a supervisory authority at any time if you believe that data processing has taken place in violation of applicable law.

D. Existence of automated individual decision making, including profiling

Automated individual decision making / profiling does not take place on this website

E. Applicant data

a) What data and sources do we use

We process the following categories of personal data:

• Contact information and personal data, in particular first and last name, title if applicable, address, telephone number, email address;

• qualification-related information, in particular academic achievements and other information contained in the curriculum vitae, including information on awards and scholarships and extra-curricular achievements, information on dissertation projects, details of training and work experience, copies of references and certificates;

• Photographs attached to an application, if applicable;

• If applicable, information on (possibly only planned or hoped for) future education and other career steps as well as professional focus areas and interests.

In principle, we collect this data directly from you. In addition, if this is necessary for the decision on the establishment of an employment relationship, we process personal data that we permissibly obtain from publicly accessible sources (e.g. professional networks on the internet). In addition, we may have received data from third parties (e.g. headhunters).

b) Purpose of data collection and legal basis

If you make use of the option to apply online via our website, we process the above mentioned data insofar as this is necessary to carry out the application procedure. The legal basis for this processing is Art. 6 para. 1 lit. b GDPR paragraph 26 FDPA in conjunction with Art. 88 GDPR.

c) Recipients of your personal data

Internally, your personal data will be forwarded to the responsible and decision-making managing directors and employees. Our central Serafin HR department supports the Serafin group companies in the execution of the recruiting and application process as a service provider. The respective group companies filling the position remain those responsible for data protection.

d) Retention period

As a rule, your personal data will be automatically deleted six months after completion of the respective application procedure. This does not apply if legal regulations prevent deletion, if further storage is necessary for the purpose of providing evidence or if you have expressly consented to longer storage.

e) Storage for future job advertisements

If we are unable to offer you a current vacancy but are the opinion – based on your profile – that your application may be of interest for future vacancies, we would like to continue to process your data even after the application process has been completed in order to draw your attention to other vacancies that match your profile. The prerequisite for processing is that you give us your express consent (Art. 6 para. 1 lit. b GDPR) (consent). You can revoke your consent at any time with effect for the future. The non-granting or revocation of this consent has no influence on the application process. Without your consent, however, we will unfortunately not be able to contact you for future job offers.


http://tools.google.com/dlpage/gaoptout?hl=de

You can prevent data acquisition by Google Analytics by clicking on the link above. An opt-out cookie is installed, which prevents your data from being collected when you visit this website in future.

F. Updating the privacy policy

We may amend this privacy policy from time to time as necessary due to changes in data processing practices. Please check the content of our privacy policy regularly and also to ensure that third party contact information is up to date.