The HABAU GROUP regards all data as an asset worth protecting. The protection of your personal data is our highest priority.
Personenbezogene Daten im Sinne des Datenschutzrechts sind alle Daten, die Angaben über persönliche oder sachliche Verhältnisse enthalten, beispielsweise Name, Anschrift, E-Mail-Adresse, Telefonnummer, Geburtsdatum, Alter, Geschlecht, Sozialversicherungsnummer, Videoaufzeichnungen, Fotos und Stimmaufnahmen von Personen. Auch sensible Daten, wie Gesundheitsdaten oder Daten im Zusammenhang mit einem Strafverfahren, können mitumfasst sein.
Personal data in terms of data protection law are all data that contain information regarding personal or factual circumstances, for example name, address, email address, telephone number, date of birth, age, gender, social insurance number, video recordings, photos and voice recordings of persons. This may also include sensitive data, such as health data or data in connection with a criminal proceeding.
Your personal data is processed confidentially and exclusively in the context of the data protection provisions (General Data Protection Regulation, or GDPR for short, and national data protection provisions) in the currently applicable version. With regard to the terms used, such as “processing”, “data controller” or “data subject”, please refer to the definitions found in Art. 4 of the GDPR.
Der einfachen Lesbarkeit halber wird die männliche Form verwendet. Die Ausführungen beziehen sich jedoch gleichermaßen auf weibliche und männliche Personen.
1. Area of application
2. Legal basis of processing personal data
Your data is processed on the legal basis of
the performance of the contract or pre-contractual measures with the respective (potential) partners, customers and suppliers as well as employees and applicants,
data processing due to a legal obligation,
the performance of a duty which is in the interest of the general public,
a legitimate interest.
3. Purposes of the processing
3.1. Processing of applicant data
We process the applicant data submitted by you via email, online form or post exclusively for the purpose of handling the application procedure.
In the event of a successful application, the data provided by you may be further processed and stored by us for the purposes of an employment relationship. Otherwise, the data will be automatically deleted at the latest seven months after notification of the rejection decision, unless this is contrary to any other legitimate interests of the data controller or unless the applicant has provided consent to further processing.
In the event of an unsolicited application or if you grant consent to have your application kept on file, your application may be forwarded to a company of HABAU GROUP, where it will be stored until a revocation of the granted consent is received.
3.2. Processing the data of our partners, customers and suppliers
In order to fulfil our contractual and pre-contractual obligations, various personal data of our partners, customers and suppliers is processed. Your data is used, among other things, to guarantee smooth correspondence and to optimise ongoing business relations.
Within the HABAU GROUP, the processing of your data takes place on the basis of the fulfilment of the contract or pre-contractual measures in accordance with Art. 6 Para. 1 Item b GDPR as well as on the basis of legitimate interests in accordance with Art. 6 Para. 1 Item f GDPR, namely the legitimate interests of the HABAU GROUP in the optimisation of the business relations.
You have the right to object to the processing. The objection must be addressed to email@example.com.
3.3. Getting in touch via email or via a form on our website
The primary objective of our website is to inform you of our scope of activity and to provide you with suitable options for getting in touch with us.
When you get in contact with us using the contact form or via email, your details are automatically stored and processed for the exclusive purpose of responding to your inquiry. Unless this inquiry gives rise to other legal retention periods, these personal data are deleted within 90 days.
3.4. Server log data
The providers of our web pages automatically process information in so-called server log files, which your internet browser automatically transmits to us. This information includes browser type and browser version, operating system used, referrer URL, host name of the accessing computer, time of server inquiry and IP address. This data is not brought into connection with any other data sources.
3.5. Website analysis, tracking and cookies
Our websites sometimes use so-called cookies. Cookies are small text files that are deposited on your terminal device and that your internet browser stores. Cookies are used on the basis of a legitimate interest in the optimised provision of our services free from technical errors. Most of the cookies used by us are so-called ‘session cookies’. These are automatically deleted after the end of your visit. Other cookies remain stored on your terminal device until you delete them. These cookies enable us to recognise your internet browser next time you visit our website. You can set your internet browser so that you are informed when cookies are placed and only allow cookies on a case-by-case basis, so that you exclude the acceptance of cookies in specific cases or generally, and activate the automatic deletion of cookies when you close the internet browser. Deactivating cookies may limit the functionality of these web pages.
3.6. Plugins and Tools
- Google Maps
We use an API of the map service Google Maps on our web pages in order to create a legitimate interest in a uniform, appealing web presence and to make it easier to access the places shown on our web pages. To use the functions of this service, your IP address is transmitted to the Google server in the USA and processed there. We have no access to the information transmitted to Google. Further details are available at
We use YouTube plugins on our web pages due to a legitimate interest in establishing a uniform, appealing web presence. When you visit our web pages with the YouTube plug-in, your IP address and the visiting behaviour of the web pages is processed by YouTube in the USA. If you are logged in to YouTube, this information is linked to your profile. You may prevent this information from being transmitted to YouTube by being logged out of YouTube before you visit our web pages.
- Google Web Fonts
We use Google Web Fonts where necessary on our web pages due to a legitimate interest in establishing a uniform, appealing web presence. When you access one of our web pages, your internet browser loads the necessary Web Fonts in your browser cache in order to display texts and fonts correctly. When you download these texts and fonts, your internet browser transmits your IP address to the Google server in the USA. Please refer to https://developers.google.com/fonts/faq for more details. We would like to note that the functionality of our web pages may be limited if your internet browser does not support this service.
- Facebook Pixel
Intended purpose: Facebook uses this cookie to display advertising products.
Date of expiry: after 3 months
Intended purpose: This cookie is used to ensure that the Facebook pixel functions properly.
Date of expiry: after 3 months
Value: Name of the author
Intended purpose: This cookie stores the text and name of a user who, for example, leaves a comment.
Date of expiry: after 12 months
Value: https%3A%2F%2Fwww.testseite…%2F (URL of the author)
Intended purpose: This cookie stores the URL of the website that the user enters in a text field on our website.
Date of expiry: after 12 months
Value: Email address of the author
Intended purpose: This cookie stores the email address of the user if he has provided it on the website.
Date of expiry: after 12 months
If you are registered with Facebook, you can change your settings for advertisements yourself at https://www.facebook.com/ads/preferences/?entry_product=ad_settings_screen. If you are not a Facebook user, you can manage your usage-based online advertising in general at http://www.youronlinechoices.com/de/praferenzmanagement/. There, you have the option to deactivate or activate providers.
If you wish to find out more about Facebook’s data privacy, we recommend that you read the company’s own data policy at https://www.facebook.com/policy.php.
- Google Analytics (with anonymisation feature)
We use the EarlyBird software from Conbrain Solutions GmbH for individual selected construction projects on the basis of a legitimate interest in ensuring early detection of execution-critical issues. The complete contents of all incoming and outgoing emails of select construction project email addresses are processed automatically. Here, we explicitly note that this communication data also contains personal data. No automated or non-automated decisions are made at any time using the software based on the personal data contained in the respective emails. Please refer to
https://www.conbrain.solutions/datenschutz/ for more details.
4. Data transmission
Within the HABAU GROUP, personal data is exchanged in order to meet the necessary legal requirements and to streamline our operational processes.
In the course of the contractual and pre-contractual activity (potential employees/customers/suppliers), it may be necessary for personal data to be transmitted to other companies within as well as outside of the European Economic Area. In these countries, to some extent there is a lower level of data protection than in the European Union.
When we forward personal data, we arrange for appropriate guarantees for the data transmission, such that an adequate level of protection is ensured. You may ask to be sent a copy of the security measures.
We differentiate between the following categories of recipients of personal data in HABAU GROUP:
- Subcontractors, general contractors, suppliers
- Processors, insofar as they require the data for the performance of their respective services
- Authorities, public bodies and institutions
- Notaries, legal and tax advisers, collection service providers and experts for asserting, exercising or defending legal claims
- Auditing companies for the fulfilment of accounting obligations
- Insurance companies
- Credit and financial institutions or comparable institutions
- Courts for the assertion, exercise or defence of legal claims
- Arbitration bodies
5. Data retention period
Personal data which is processed by us is only stored until the purpose for which it is being processed is fulfilled. Criteria for storage are:
Insofar as retention periods related to corporate and fiscal law must be observed, the duration of the storage of certain data may last up to seven years. Further criteria for the storage are, among others, claims related to civil and labour law (depending on the legal basis, may last up to 30 years).
6. Technical and organisational measures
The HABAU GROUP’s fundamental goals within the context of information security include the realisation of appropriate availability, confidentiality and integrity as well as ensuring data protection. This understanding of protection applies not only to personal data, but also to all other information processed in our company.
Our technical and organisational measures in information security are in line with the latest technology and are based on internationally recognised standards and norms. As part of a management system, these are regularly evaluated and improved.
7. Your rights as a data subject
As a data subject, you reserve the following rights with regard to the processing of your data:
7.1. Right of access
You may request information on the type and content of the processing of your data as well as on the data stored on you at any time. At your request, the data controller must issue a confirmation of the use of your data.
7.2. Right to rectification
You have the right to request the rectification of incorrect data. Depending on the purpose of the processing, you also have the right to the completion of incomplete data by means of a supplementary statement.
7.3. Right to erasure
You may request the deletion of your data at any time. The data controller is obliged to delete the data concerned immediately unless legitimate grounds dictate otherwise.
7.4. Right to restrict processing
You have the right to request the restriction of the processing of your data unless legitimate grounds dictate otherwise.
7.5. Right to data portability
You have the right to receive the data provided to the data controller in a structured, common and machine-readable format. You also have the right to transmit these data to another data controller without obstruction by the data controller to whom the data was made available, unless legitimate grounds dictate otherwise.
7.6. Right to withdrawal of consent
You have the right to revoke your consent unless the processing occurs based on other grounds stipulated by law. For this, an informal notification via email to firstname.lastname@example.org is sufficient. The revocation of this consent has no effect on the processing that has already taken place.
7.7. Right to object
You have the right to objection unless the processing is necessary for the performance of a task, is of public interest and is carried out in the exercise of official authority that was transferred to the data controller or is necessary for the protection of the legitimate interests of the data controller or a third party, unless your interests or basic rights and freedoms that require the protection of the data outweigh these interests.
Please direct your questions on the exercise of your data subject rights or other questions regarding data protection directly to email@example.com If you believe that the HABAU GROUP is not observing your data protection rights in accordance with the law, you are free to lodge a complaint with the responsible supervisory authority.
If your personal data changes, we request immediate corresponding notification thereof.
8. Point of contact for data protection matters
Insofar as a legal appointment of a data protection officer is required, we have accordingly appointed one and informed the respective supervisory authority thereof. As the central point of contact for all data protection matters, you can reach them by sending an email to firstname.lastname@example.org at any time. Your inquiry will be forwarded to the responsible employee for processing.
9. Changes to this data privacy statement
In the course of ongoing development, this data privacy statement will continue to be adapted. Changes will be announced on our web pages in good time. Thus you should regularly read this data privacy statement in order to stay up to date with the latest version.
Stand: April 2021, Revision 1.3