Privacy policy

The HABAU GROUP regards all data as an asset worth protecting. The protection of your personal data is our highest priority.

Personenbezogene Daten im Sinne des Datenschutzrechts sind alle Daten, die Angaben über persönliche oder sachliche Verhältnisse enthalten, beispielsweise Name, Anschrift, E-Mail-Adresse, Telefonnummer, Geburtsdatum, Alter, Geschlecht, Sozialversicherungsnummer, Videoaufzeichnungen, Fotos und Stimmaufnahmen von Personen. Auch sensible Daten, wie Gesundheitsdaten oder Daten im Zusammenhang mit einem Strafverfahren, können mitumfasst sein.

Personal data in terms of data protection law are all data that contain information regarding personal or factual circumstances, for example name, address, email address, telephone number, date of birth, age, gender, social insurance number, video recordings, photos and voice recordings of persons. This may also include sensitive data, such as health data or data in connection with a criminal proceeding.

Your personal data is processed confidentially and exclusively in the context of the data protection provisions (General Data Protection Regulation, or GDPR for short, and national data protection provisions) in the currently applicable version. With regard to the terms used, such as “processing”, “data controller” or “data subject”, please refer to the definitions found in Art. 4 of the GDPR.

Der einfachen Lesbarkeit halber wird die männliche Form verwendet. Die Ausführungen beziehen sich jedoch gleichermaßen auf weibliche und männliche Personen.

 

1. Area of application

This Privacy Policy regulates the handling and processing of personal data, and applies to all employees of HABAU GROUP and to all other persons integrated in the business, as well as to our partners, customers and suppliers. The HABAU GROUP comprises all subsidiaries and other associated companies. You can find the contact partners for each subsidiary in the respective imprints, available under Contact.

 

2. Legal basis of processing personal data

Your data is processed on the legal basis of

the performance of the contract or pre-contractual measures with the respective (potential) partners, customers and suppliers as well as employees and applicants,
consent,
data processing due to a legal obligation,
the performance of a duty which is in the interest of the general public,
a legitimate interest.

 

3. Purposes of the processing

 

3.1. Processing of applicant data

We process the applicant data submitted by you via email, online form or post exclusively for the purpose of handling the application procedure.

In the event of a successful application, the data provided by you may be further processed and stored by us for the purposes of an employment relationship. Otherwise, the data will be automatically deleted at the latest seven months after notification of the rejection decision, unless this is contrary to any other legitimate interests of the data controller or unless the applicant has provided consent to further processing.

In the event of an unsolicited application or if you grant consent to have your application kept on file, your application may be forwarded to a company of HABAU GROUP, where it will be stored until a revocation of the granted consent is received.

3.2. Processing the data of our partners, customers and suppliers

In order to fulfil our contractual and pre-contractual obligations, various personal data of our partners, customers and suppliers is processed. Your data is used, among other things, to guarantee smooth correspondence and to optimise ongoing business relations.

Within the HABAU GROUP, the processing of your data takes place on the basis of the fulfilment of the contract or pre-contractual measures in accordance with Art. 6 Para. 1 Item b GDPR as well as on the basis of legitimate interests in accordance with Art. 6 Para. 1 Item f GDPR, namely the legitimate interests of the HABAU GROUP in the optimisation of the business relations.

You have the right to object to the processing. The objection must be addressed to ds-hg@habau.at.

 

3.3. Getting in touch via email or via a form on our website

The primary objective of our website is to inform you of our scope of activity and to provide you with suitable options for getting in touch with us.

When you get in contact with us using the contact form or via email, your details are automatically stored and processed for the exclusive purpose of responding to your inquiry. Unless this inquiry gives rise to other legal retention periods, these personal data are deleted within 90 days.

 

3.4. Server log data

The providers of our web pages automatically process information in so-called server log files, which your internet browser automatically transmits to us. This information includes browser type and browser version, operating system used, referrer URL, host name of the accessing computer, time of server inquiry and IP address. This data is not brought into connection with any other data sources.

 

3.5. Website analysis, tracking and cookies

Our websites sometimes use so-called cookies. Cookies are small text files that are deposited on your terminal device and that your internet browser stores. Cookies are used on the basis of a legitimate interest in the optimised provision of our services free from technical errors. Most of the cookies used by us are so-called ‘session cookies’. These are automatically deleted after the end of your visit. Other cookies remain stored on your terminal device until you delete them. These cookies enable us to recognise your internet browser next time you visit our website. You can set your internet browser so that you are informed when cookies are placed and only allow cookies on a case-by-case basis, so that you exclude the acceptance of cookies in specific cases or generally, and activate the automatic deletion of cookies when you close the internet browser. Deactivating cookies may limit the functionality of these web pages.

 

3.6. Plugins and Tools

  • Google Maps
    We use an API of the map service Google Maps on our web pages in order to create a legitimate interest in a uniform, appealing web presence and to make it easier to access the places shown on our web pages. To use the functions of this service, your IP address is transmitted to the Google server in the USA and processed there. We have no access to the information transmitted to Google. Further details are available at
    https://www.google.de/intl/de/policies/privacy/.
  • YouTube
    We use YouTube plugins on our web pages due to a legitimate interest in establishing a uniform, appealing web presence. When you visit our web pages with the YouTube plug-in, your IP address and the visiting behaviour of the web pages is processed by YouTube in the USA. If you are logged in to YouTube, this information is linked to your profile. You may prevent this information from being transmitted to YouTube by being logged out of YouTube before you visit our web pages.
  • Google Web Fonts
    We use Google Web Fonts where necessary on our web pages due to a legitimate interest in establishing a uniform, appealing web presence. When you access one of our web pages, your internet browser loads the necessary Web Fonts in your browser cache in order to display texts and fonts correctly. When you download these texts and fonts, your internet browser transmits your IP address to the Google server in the USA. Please refer to https://developers.google.com/fonts/faq for more details. We would like to note that the functionality of our web pages may be limited if your internet browser does not support this service.
  • Facebook
    We use Facebook plug-ins as necessary on our web pages. When you visit our web pages with the Facebook plug-in (recognisable by the Facebook logo), your IP address and the visiting behaviour of the web pages is processed by Facebook in the USA. If you are logged in to Facebook, this information is linked to your profile. On these web pages, you can activate the “Like” function in order to share this information in Facebook. We have no access to the information transmitted to Google. Further details are available at https://www.facebook.com/policies. You may prevent this Privacy Policy GDPR page 2 information from being transmitted to Facebook by being logged out of Facebook before you visit our web pages.
  • Facebook Pixel
    We use the Facebook pixel by Facebook on our website. For this purpose, we have implemented a code on our website. The Facebook pixel is an excerpt of JavaScript code that loads a collection of functions with which Facebook is able to track your user actions if you have accessed our website via Facebook ads. If, for example, you purchase a product on our website, the Facebook pixel is activated and stores your actions on our website in one or more cookies. These cookies enable Facebook to compare your user data (customer data such as IP address, user ID) with the data from your Facebook account. After this, Facebook deletes this data once more. The collected data remains anonymous and cannot be viewed by us, and can only be used within the context of placing advertisements. If you yourself are a Facebook user and are logged in, your visit to our website is automatically assigned to your Facebook user account.We only want to show our services and products to the people who are actually interested in them. The Facebook pixel makes it possible to better adjust our advertising measures to suit your desires and interests. In this way, Facebook users are shown appropriate advertising (if they have enabled personalised advertising). Furthermore, Facebook also uses the collected data for analysis purposes and its own advertising purposes.Below is a list of the cookies that were placed on a test page when the Facebook pixel was integrated. Please note that these are merely examples of cookies. Depending on the interaction on our website, different cookies are placed.

    Name: _fbp
    Value: fb.1.1568287647279.257405483-6211148565-7
    Intended purpose: Facebook uses this cookie to display advertising products.
    Date of expiry: after 3 months

    Name: fr
    Value: 0aPf312HOS5Pboo2r..Bdeiuf…1.0.Bdeiuf.
    Intended purpose: This cookie is used to ensure that the Facebook pixel functions properly.
    Date of expiry: after 3 months

    Name: comment_author_50ae8267e2bdf1253ec1a5769f48e062211148565-3
    Value: Name of the author
    Intended purpose: This cookie stores the text and name of a user who, for example, leaves a comment.
    Date of expiry: after 12 months

    Name: comment_author_url_50ae8267e2bdf1253ec1a5769f48e062
    Value: https%3A%2F%2Fwww.testseite…%2F (URL of the author)
    Intended purpose: This cookie stores the URL of the website that the user enters in a text field on our website.
    Date of expiry: after 12 months

    Name: comment_author_email_50ae8267e2bdf1253ec1a5769f48e062
    Value: Email address of the author
    Intended purpose: This cookie stores the email address of the user if he has provided it on the website.
    Date of expiry: after 12 months
    Note: The above-mentioned cookies are related to individual user behaviour. When it comes to the use of cookies in particular, changes by Facebook can never be excluded.

    If you are registered with Facebook, you can change your settings for advertisements yourself at https://www.facebook.com/ads/preferences/?entry_product=ad_settings_screen. If you are not a Facebook user, you can manage your usage-based online advertising in general at http://www.youronlinechoices.com/de/praferenzmanagement/. There, you have the option to deactivate or activate providers.

    If you wish to find out more about Facebook’s data privacy, we recommend that you read the company’s own data policy at https://www.facebook.com/policy.php.

  • Google Analytics (with anonymisation feature)
    We use Google Analytics as necessary on our web pages. When you access our web pages, this service uses cookies to gather information on how the site is used. This information and your IP address are processed by Google servers in the USA. We use this service with and without the anonymisation function of the IP address. Based on the information evaluated by Google on your use of our web pages, we adjust our information offering on the web pages or associated services accordingly. Under certain circumstances, Google itself also has the right to process this information. You yourself can prevent the use of this service by using the necessary settings in your internet browser. However, we would like to note that these settings may lead to limitations in the use of our web pages. You can prevent your data from being processed by the service and stop your IP address from being shared with Google by installing the following plug-in
    https://tools.google.com/dlpage/gaoptout.
  • EarlyBird
    We use the EarlyBird software from Conbrain Solutions GmbH for individual selected construction projects on the basis of a legitimate interest in ensuring early detection of execution-critical issues. The complete contents of all incoming and outgoing emails of select construction project email addresses are processed automatically. Here, we explicitly note that this communication data also contains personal data. No automated or non-automated decisions are made at any time using the software based on the personal data contained in the respective emails. Please refer to
    https://www.conbrain.solutions/datenschutz/  for more details.

 

4. Data transmission

Within the HABAU GROUP, personal data is exchanged in order to meet the necessary legal requirements and to streamline our operational processes.

In the course of the contractual and pre-contractual activity (potential employees/customers/suppliers), it may be necessary for personal data to be transmitted to other companies within as well as outside of the European Economic Area. In these countries, to some extent there is a lower level of data protection than in the European Union.

When we forward personal data, we arrange for appropriate guarantees for the data transmission, such that an adequate level of protection is ensured. You may ask to be sent a copy of the security measures.

We differentiate between the following categories of recipients of personal data in HABAU GROUP:

  • Subsidiaries
  • Subcontractors, general contractors, suppliers
  • Processors, insofar as they require the data for the performance of their respective services
  • Authorities, public bodies and institutions
  • Notaries, legal and tax advisers, collection service providers and experts for asserting, exercising or defending legal claims
  • Auditing companies for the fulfilment of accounting obligations
  • Insurance companies
  • Credit and financial institutions or comparable institutions
  • Courts for the assertion, exercise or defence of legal claims
  • Arbitration bodies

 

5. Data retention period

Personal data which is processed by us is only stored until the purpose for which it is being processed is fulfilled. Criteria for storage are:

Insofar as retention periods related to corporate and fiscal law must be observed, the duration of the storage of certain data may last up to seven years. Further criteria for the storage are, among others, claims related to civil and labour law (depending on the legal basis, may last up to 30 years).

6. Technical and organisational measures

The HABAU GROUP’s fundamental goals within the context of information security include the realisation of appropriate availability, confidentiality and integrity as well as ensuring data protection. This understanding of protection applies not only to personal data, but also to all other information processed in our company.

Our technical and organisational measures in information security are in line with the latest technology and are based on internationally recognised standards and norms. As part of a management system, these are regularly evaluated and improved.

 

7. Your rights as a data subject

As a data subject, you reserve the following rights with regard to the processing of your data:

 

7.1. Right of access

You may request information on the type and content of the processing of your data as well as on the data stored on you at any time. At your request, the data controller must issue a confirmation of the use of your data.

 

7.2. Right to rectification

You have the right to request the rectification of incorrect data. Depending on the purpose of the processing, you also have the right to the completion of incomplete data by means of a supplementary statement.

 

7.3. Right to erasure

You may request the deletion of your data at any time. The data controller is obliged to delete the data concerned immediately unless legitimate grounds dictate otherwise.

 

7.4. Right to restrict processing

You have the right to request the restriction of the processing of your data unless legitimate grounds dictate otherwise.

 

7.5. Right to data portability

You have the right to receive the data provided to the data controller in a structured, common and machine-readable format. You also have the right to transmit these data to another data controller without obstruction by the data controller to whom the data was made available, unless legitimate grounds dictate otherwise.

 

7.6. Right to withdrawal of consent

You have the right to revoke your consent unless the processing occurs based on other grounds stipulated by law. For this, an informal notification via email to ds-hg@habau.at is sufficient. The revocation of this consent has no effect on the processing that has already taken place.

 

7.7. Right to object

You have the right to objection unless the processing is necessary for the performance of a task, is of public interest and is carried out in the exercise of official authority that was transferred to the data controller or is necessary for the protection of the legitimate interests of the data controller or a third party, unless your interests or basic rights and freedoms that require the protection of the data outweigh these interests.

Please direct your questions on the exercise of your data subject rights or other questions regarding data protection directly to ds-hg@habau.at If you believe that the HABAU GROUP is not observing your data protection rights in accordance with the law, you are free to lodge a complaint with the responsible supervisory authority.

If your personal data changes, we request immediate corresponding notification thereof.

 

8. Point of contact for data protection matters

Insofar as a legal appointment of a data protection officer is required, we have accordingly appointed one and informed the respective supervisory authority thereof. As the central point of contact for all data protection matters, you can reach them by sending an email to ds-hg@habau.at at any time. Your inquiry will be forwarded to the responsible employee for processing.

9. Changes to this data privacy statement

In the course of ongoing development, this data privacy statement will continue to be adapted. Changes will be announced on our web pages in good time. Thus you should regularly read this data privacy statement in order to stay up to date with the latest version.

Stand: April 2021, Revision 1.3