Data processing on this website
For the RATISBONA Handelsimmobilien compliance with data protection laws is not only a legal obligation, but a necessary element of trust. In the following we want to transparently inform you about the methods, scope and purpose of the processing of your personal data which might be collected from you while visiting this website. We will also inform you about your rights.
Data protection officer
You can reach our DPO at:
Süddeutsche Datenschutzgesellschaft mbH
c/o Maximilian Mayer
Tel: +49 (0) 941 - 38177070
Rights of the data subject
Your rights as a data subject
As a data subject you have the following rights concerning your personal data. You have
- the right of access to information on – among others – the purposes of the processing, the categories of personal data concerned, the envisaged period for which the personal data will be stored as well as possible recipients, pursuant to and in accordance with the requirements of Art. 15 GDPR and § 34 BDSG
- the right to rectification and to erasure of incorrect or incomplete data pursuant to and in accordance with the requirements of Art. 16 and 17 GDPR and § 35 BDSG.
- the right to restriction of processing pursuant to and in accordance with the requirements of Art. 18 GDPR and § 35 (1) 2 BDSG.
- the right to object, on grounds relating to your particular situation, to the processing of personal data concerning you which is based on point (e) or (f) of Article 6(1) pursuant to and in accordance with the requirements of Art. 21 (1) GDPR.
- the right to withdraw your given consent at any time, which does, however, not affect the lawfulness of processing based on consent before its withdrawal according to Art. 7 (3) GDPR.
- the right to data portability in a structured, commonly used and machine-readable format pursuant to and in accordance with the requirements of Art. 20 GDPR
- You have, pursuant to and in accordance with the requirements of Art. 22 GDPR, the right not to be subject to a decision based solely on automated processing, including profiling, which entails legal effects concerning you or significantly affects you in a similar way.
- Furthermore pursuant to Art. 77 GDPR you have the right to lodge a complaint with a supervisory authority about the processing of your personal data by us, in particular in the member state of your habitual residence, place of work or place of the alleged infringement.
When you claim your rights toward us according to the GDPR and the BDSG, we will process the data you thereby submit to fulfill your claims.
Subsequently we will store the data submitted by you and the data submitted by us to you in return for the purpose of documentation until the expiry of the regulatory offenses limitation period (3 years).
The lawfulness of processing and storing the data is based on Art. 6 (1) point (f) GDPR (legitimate interest of data processing). The legitimate interest results from our obligation to fulfill your requests and the need to exonerate ourselves in possible fine proceedings by proving that we have lawfully fulfilled your requests.
You can object to the processing of your personal data based on our legitimate interest at any time under the premises of Art. 21 GDPR. Please use the contact details provided in the imprint. We would like to note that the processing of your personal data is mandatory for the verification of compliance with data protection rights of the data subject according to Art. 21 (1) GDPR, as other methods of verification do not exist or are not equally suitable.
Data protection measures / arrangements
We secure our website and other systems — and thus your data — through technical and organizational measures against loss, destruction, access, change or dissemination through unauthorized persons. In particular your personal data will be transmitted encrypted through the internet. Therefore we operate with the coding system TLS (Transport Layer Security).
Having said this, the transmission of information via internet is never fully safe, which is why we cannot guarantee the safety of the data transmitted by our website to a 100%.
Data processing modalities
Sources and categories of personal data
We process your personal data insofar as it is necessary for the statement, content-related configuration or modification of a contractual relationship between you and us (inventory data). In particular the following can be inventory data: Name, form of address, contact details (postal address, telephone, email address), date of birth , etc.
Furthermore we process your usage data. Usage data is data that is collected when you interact with our web content and our services, in particular your IP address, start and end of your visit on our website and information on the contents you have viewed on our website.
We collect the data mentioned directly from you (e.g., through the visit of our website), or, provided that it is permitted by data protection laws, from third parties or respectively from publicly accessible sources (e.g., commercial or association register, the press, media, internet).
Data transfer to third party countries outside the EU
All information we acquire from or on you will generally be processed on servers located within the European Union. A transmission of your data or a processing of your data in third party countries will occur without your explicit consent solely if this is legally intended or permitted and if an appropriate data protection level is guaranteed in the third party country.
Data disclosure, processing on behalf of the Controller
We will never illicitly disclose your personal data to third parties. However, we may disclose your data to third parties, in particular if you have agreed to data disclosure, if the disclosure is necessary to fulfill our legal obligations or if we are obligated or authorized to disclose said data by law or administrative or judicial orders. In particular this may be the case for the purposes of criminal proceedings, averting of dangers or enforcement of intellectual property rights.
Under certain circumstances we may transmit your data to external service providers which process data on our behalf and in accordance with our instructions (data processor) to simplify and disburden our own data processing. Every data processor will be bound by contract according to Art. 28 GDPR. In particular this means that the data processor has to offer sufficient guarantees that appropriate technical and organizational measures are implemented so that data processing is compliant with the requirements of the GDPR and your rights as a data subject are ensured. Despite commissioning data processors we remain the responsible party for the processing of your personal data according to the GDPR.
Purpose / Objective of the data processing
In general we will use the data solely for the purpose for which the data was gathered. We may subsequently process the data for another, different purpose, provided that this other purpose is not incompatible with the original purpose (Art. 5 (1) point (c) GDPR).
Unless specified otherwise, we will store data gathered from you only for as long as it is necessary for each respective purpose and unless there are legal retention obligations preventing deletion, for example from commercial law or tax law.
Individual processing activities / operations
In the following we want to outline as transparently as possible, which of your data we will process under which circumstances, on what basis and for what purpose.
Server log files
Each time our website is accessed, the following general information will be automatically sent to our servers by your browser (so called server log files): Your IP address, product and version information of the browser and operating system used (so called user agent), the webpage from which the access originated (so called referer), date and time of the request and possibly your internet service provider. Furthermore the status and the volume of data will be recorded.
Your computer’s IP address will be stored only for the duration of your visit to the website and subsequently will immediately be deleted or made partially unrecognizable through reduction. The rest of the data will be stored for a limited period of time (to a maximum of 7 days).
The legal basis for the usage of these server log files is Art. 6 (1) point (f) GDPR (legitimate interest of data processing). The legitimate interest arises from the necessity to operate our website, especially to discover and remove website errors, to determine the utilization of the webpage, to make adjustments and improvements and to guarantee the security of the system. You can object to the processing of your personal data based on the legitimate interest at any time under the premises of Art. 21 GDPR. Please use the contact details provided in the imprint. We would like to point out that the processing of your server log files is mandatory in accordance with Art. 21 (1) GDPR, as otherwise the website cannot be operated at all.
Third party services
For simplification of our data processing and to extend the functionality of our website we use third party services and resources, for example plugins, external content, software or other external service providers (services). In doing so the possibility exists that personal data will be transmitted to the service provider. If required, to protect your data, we have contractually obligated the service provider according to Art. 28 GDPR to solely process the data according to our instructions. We would like to explicitly point out that we are regularly only responsible for the data acquisition and transmission by the service according to the GDPR, but not for a possible subsequential processing by the respective service provider.
In detail we use the following services:
Our webpage uses services from the company Google Ireland Limited ("Google EU"), Gordon House, Barrow Street, Dublin 4, Irland. This company represents the company Google LLC ("Google US"), 1600 Amphitheatre Parkway Mountain View, CA 94043, USA in the EU. The company Google US fulfills the requirements of the "EU-US-privacy-shield". The Privacy-shield-agreement regulates the protection of personal data that is transmitted from an European Union member country to the USA. It ensures that the transmitted data will be subject to a data protection standard comparable to the one of the European Union. You can find the list of certified companies here: https://www.privacyshield.gov/list
By using the services data will be transmitted to Google EU and possibly from Google EU to Google US. Google as a whole can use the transmitted data to create anonymized user profiles for statistical purposes. In addition, if you possess a Google-account and are logged into it, Google can associate the transmitted data with your account, even across multiple devices. In general we do not have any influence regarding this data processing. Controller of this data processing is therefore Google EU.
You can change your individual Google ad-settings on the following website: https://adssettings.google.com/?hl=de (Please note: The settings made are deleted when you delete the cookies in your browser)
Our website uses the external font-service "Google Fonts" by Google. This service allows us to present our website in a unified and appealing way even for variously configured user terminals by loading fonts from an external server instead of the user terminal. For this purpose the required fonts will generally be requested from a Google server in the USA. Through this request the following information, amongst others, will be transmitted to the Google servers and stored there: Your IP address, product- and version information about the used browser and operating system (so called user agent), the webpage from which your access took place (so called referrer), date and time of your request and possibly your internet-service-provider.
The legal basis for the usage of Google Fonts is Art. 6 (1) point (f) GDPR (legitimate interest of data processing). The legitimate interest results from our need to present our website and online services in an appealing and unified way. You can object to the processing of your personal data based on the legitimate interest at any time under the premises of Art. 21 GDPR. Please use the contact details provided in the imprint.
We use certain services to fill and supplement our website with digital content. For this we generally use the integration functions of external platforms. By requesting content from the server of the service provider certain data will be generally transmitted to the service provider and stored there, for example your IP address, product- and version information about the used browser and operating system (so called user agent), the webpage from which your access took place (so called referrer), date and time of your request and possibly your internet-service-provider.
The legal basis for the usage of media services is Art. 6 (1) point (f) GDPR (legitimate interest of data processing). The legitimate interest results from our need to be able to offer you an optically and content wise appealing website. You can object to the processing of your personal data based on the legitimate interest at any time under the premises of Art. 21 GDPR. Please use the contact details provided in the imprint.
Social media fan pages
In addition to our website we maintain an online presence on social platforms in order to communicate with our active customers, interested parties and users, and to inform them about our services.
When you visit our presence on a social platform, your data will generally be gathered and processed by the respective platform provider for our market research and advertisement purposes. The provider can also process the data for their own purposes. From your user behavior and your interest resulting from this behavior user profiles can be made. These user profiles can in turn be used to, for example, show advertisements within and outside of the platform, that presumably corresponds with your interests. For these purposes cookies (see above) are generally stored on your terminal device, in which your user behavior and your interests will be recorded. Especially if you are a member of the respective platform and are logged in, further data may be stored independently in the user profiles. For a detailed presentation of each respective data processing and the possible contradiction possibilities we point to the following linked details of the service providers, as only they fully know the exact procedures of their data processing.
We point out, that your data may also be processed outside of the European Union. This can yield risks, as for example the enforcement of your rights may be more difficult.
The legal basis for the usage of online presences and the data procession related to it is generally Art. 6 (1) point (f) GDPR (legitimate interest of data processing). The legitimate interest results from our need to be able to present ourselves to visitors in social media as well as having the ability to introduce statements of all sorts into the media- and opinion market. You can object to the processing of your personal data based on the legitimate interest at any time under the premises of Art. 21 GDPR. Please use the contact details provided in the imprint.
The legal basis for the usage of statistical data of all visitors on our social media sites, that is gathered, prepared and made available to us by the respective platform providers is Art. 6 (1) point (f) GDPR (legitimate interest of data processing). The legitimate interest results from our need for user-oriented improvements of our online services and design and the optimization of the communication with interested parties by analysing anonymised visitor- and user behaviour. You can object to the processing of your personal data based on the legitimate interest at any time under the premises of Art. 21 GDPR. Please use the contact details provided in the imprint.
If you are asked for consent regarding data processing by the respective service provider, the legal basis for data processing is Art. 6 (1) point (a) GDPR (consent of the data subject). You can revoke your consent with effect for the future at any time. Please contact the service provider that asked for your consent regarding this.
In the event that you would like to assert your rights, we note that these rights, regardless of a possible joint responsibility and control, are most effectively enforced against the respective service provider. As a rule only the service providers have direct access to your data and can take appropriate measures directly or provide information. Should you need help nonetheless, you can contact us at any time and we will support you in the scope of our possibilities.
We are represented on:
Linked In is a social network of LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland. The company LinkedIn Ireland Unlimited Company is the European subsidiary company of the LinkedIn Corporation, 100 W. Maude Ave., Sunnyvale, California 94085, USA. The LinkedIN Corporation fulfills the requirements of the "EU-US-privacy-shield". The Privacy-shield-agreement regulates the protection of personal data that is transmitted from a European Union member country to the USA. It ensures that the transmitted data will be subject to a data protection standard comparable to the one of the European Union. You can find the list of certified companies here: https://www.privacyshield.gov/list.
Xing is a social network of the Xing AG, Dammtorstraße 29-32, 20354 Hamburg, Germany.
Effective: 07.04.2020 : 07.04.2020 Quelle: Süddeutsche Datenschutzgesellschaft mbH