Privacy Policy
Relevant legal bases
In accordance with Art. 13 DSGVO we inform you about the legal basis of our data processing. Unless the legal basis in the data protection declaration is mentioned, the following applies: The legal basis for obtaining consent is Art. 6 para. 1 lit. a and Art. 7 DSGVO, the legal basis for the processing for the performance of our services and the execution of contractual measures as well as the response to inquiries is Art. 6 para. 1 lit. b DSGVO, the legal basis for processing in order to fulfill our legal obligations is Art. 6 para. 1 lit. c DSGVO, and the legal basis for processing for the protection of our legitimate interests is Art. 6 para. 1 lit. f DSGVO. In the event that vital interests of the data subject or any other natural person require the processing of personal data, Art. 6 para. 1 lit. d DSGVO as legal basis.
Changes and Updates to the Privacy Policy
We ask you to regularly inform yourself about the content of our privacy policy. We will adjust the Privacy Policy as soon as the changes to the data processing we make require it. We will inform you as soon as the changes require your participation (eg consent) or other individual notification.
Security Measures:
In accordance with Article 32 of the GDPR, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, we implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk. These measures include, in particular, ensuring the confidentiality, integrity, and availability of data by controlling physical access to the data, as well as access to, input of, disclosure of, and ensuring the availability and separation of the data. Furthermore, we have established procedures to ensure the exercise of data subject rights, the erasure of data, and the response to data breaches. We also consider the protection of personal data during the development and selection of hardware, software, and processes, in accordance with the principles of data protection by design and by default (Article 25 of the GDPR).
The security measures include, in particular, the encrypted transmission of data between your browser and our server.
Collaboration with processors and third parties
If, in the context of our processing, we disclose data to other persons and companies (contract processors or third parties), transmit them to them or otherwise grant access to the data, this will only be done on the basis of a legal permission (eg if a transmission of the data to third parties, as to payment service providers, in accordance with Art. 6 para. 1 lit. b DSGVO is required to fulfill the contract), you have consented to a legal obligation or on the basis of our legitimate interests (eg the use of agents, webhosters, etc.).
If we commission third parties to process data on the basis of a so-called "order processing contract", this is done on the basis of Art. 28 DSGVO.
Data transfer to third countries
Except for the applications mentioned above, no data is transferred to countries outside the EU, nor is any such transfer planned.
Affected rights
You have the right to:
- Information about your stored data
- Correction and completion of your stored data
- Deletion of your data that is no longer needed
- Restriction of the processing of your data
- Revocation of granted consents with effect for the future
- Objection regarding the future processing of your data, in particular against processing for direct marketing purposes
- Receipt and transfer to other controllers of your data
Provision of contractual services
If inventory data (e.g., names, addresses, and contact details of users) is processed, this is done to fulfill our contractual obligations and services in accordance with Article 6 Paragraph 1 Letter b of the GDPR. For example, the information marked as mandatory in online forms is required for the conclusion of the contract.
Deletion of data
The data processed by us are deleted or restricted in accordance with Art. 17 and 18 DSGVO. Unless explicitly stated in this privacy policy, the data stored by us are deleted as soon as they are no longer required for their purpose and the deletion does not conflict with any statutory storage requirements. Unless the data is deleted because it is required for other and legitimate purposes, its processing will be restricted. This means that the data is blocked and not processed for other purposes. This applies, for example, to data that must be kept for commercial or tax reasons.
Contacting us
When contacting us (via contact form or e-mail), the information provided by the user for processing the contact request and processing it in accordance with Art. 6 para. 1 lit. b) GDPR processed.
User data may be stored in a Customer Relationship Management system (“CRM system”) or similar inquiry management system.
We delete the inquiries if they are no longer required. We review the requirement every two years; We permanently save inquiries from customers who have a customer account and refer to the information on the customer account for deletion. In the case of the legal archiving obligations, the deletion takes place after their expiry (end of commercial law (6 years) and tax law (10 years) retention obligation).
Collection of access data and log files
Based on our legitimate interests pursuant to Art. 6 para. 1 lit. f GDPR, we collect data about every access to the server on which this service is located (so-called server log files). Access data includes the name of the accessed website, file, date and time of access, amount of data transferred, notification of successful access, browser type and version, the user's operating system, referrer URL (the previously visited page), IP address, and the requesting provider.
Log file information is stored for a maximum of seven days for security reasons (e.g., to investigate misuse or fraud) and then deleted. Data that needs to be retained for evidentiary purposes is exempt from deletion until the respective incident has been fully resolved.
Online presence in social media
We operate online presences within social networks and platforms based on our legitimate interests pursuant to Art. 6 para. 1 lit. f GDPR in order to communicate with customers, prospective customers and users active there and to inform them about our services. When accessing the respective networks and platforms, the terms and conditions and data processing policies of their respective operators apply.
Unless otherwise stated in our privacy policy, we process the users' data as far as they communicate with us within the social networks and platforms, eg write articles on our online presence or send us messages.
Supervisory authority
According to Article 77 of the EU GDPR, you can lodge a complaint with a supervisory authority if you believe that the processing of your personal data violates the EU GDPR or the BDSG.
The State Commissioner for Data Protection and Freedom of Information
Lautenschlagerstrasse 20
70173 Stuttgart
Phone: 0711 6155410
Email: poststelle@lfdi.bwl.de
Data protection officer
External data protection officer appointed via
WTS Wohnungswirtschaftliche Treuhand Stuttgart GmbH
Hohe Straße 16, 70174 Stuttgart
Phone: 0711 16345410
Email: dsb-wts@wts-vbw.de
Downloads
Information obligation – Employment of employees
Information obligation – Rental sector