Controller:
GKW Consult GmbH
Augustaanlage 67
68165 Mannheim – Germany
Phone: +49 621 41077 0
E-mail: info@gkw-consult.com
Contact details of the Data Protection Officer
E-mail: datenschutz@gfa-holding.de
Competent supervisory authority:
The State Commissioner for Data Protection and Freedom of Information Baden-Württemberg
https://www.baden-wuerttemberg.datenschutz.de/
This Data Privacy Statement is also valid for our Branch Offices located in India, Bulgaria, Burkina Faso, Tanzania, Morocco, Tunisia, Colombia, and Peru.
Data privacy
GKW Consult GmbH, which operates this website, takes the protection of your personal data very seriously. We treat your personal data confidentially in accordance with statutory data protection regulations and this Data Privacy Statement.
In principle, you can use our website without actively providing any personal data; however, for technical reasons, access data (e.g. server log files) is processed. Where personal data (such as your name, address or email address) is collected on our website, this is done on a voluntary basis wherever possible. This data will only be passed on to third parties where necessary.
Please note that data transmission via the internet (e.g., in the case of communication by email) may be subject to security gaps. It is not possible to protect such data completely against access by third parties.
Purpose of data collection, processing or use
GKW Consult GmbH is a consultancy firm with an international project portfolio within the GFA GROUP. Personal data may be collected, processed, used and, where necessary, transferred within the group for the purposes of acquiring, carrying out and invoicing contracts.
There is a separate expert database for acquisition and staffing purposes, in which only the contact details and CVs of experts are processed. To support the allocation of tenders and projects and to facilitate contact with suitable experts, expert data may be transferred internally within the Group to other group companies. Each group company processes the data under its own responsibility for its respective purposes (e.g. tender processing, project staffing, establishing contact).
Where we have already worked with you or where concrete project-related cooperation has been initiated, our legal basis for storing your data is Article 6(1)(f) of the GDPR (legitimate interest in identifying and contacting suitable experts for future similar projects and offers). Where registration takes place without prior collaboration, we process your data on the basis of your consent (Article 6(1)(a) of the GDPR); consent may be withdrawn at any time with effect for the future.
You may object to the processing of your data at any time pursuant to Article 21 of the GDPR, where such processing is based on Article 6(1)(f) of the GDPR. You may withdraw your consent pursuant to Article 6(1)(a) of the GDPR at any time with effect for the future. Please contact us at datenschutz[at]gfa-holding.de. We check at least every two years whether the data is still up to date and ask you to confirm this.
The Human Resources department collects, processes, uses and, where necessary, transfers personal data for internal purposes (human resources management, company pension schemes, applicant management, payroll, travel management) and to comply with social security and other legal obligations.
Description of affected groups and their related data / data categories
In the course of normal business operations, addresses, contractual and payment details, as well as data relating to electronic communications, are collected, processed and used for customers, employers, consultants, freelance experts and employees of partner companies.
The Human Resources department collects, processes and uses additional information regarding qualifications, start and end dates of employment, wage and salary information, pension and social security information, address details, security information, bank details, disciplinary notices, certificates and application documents.
Our legal basis for processing personal data in the context of ongoing contracts is Article 6(1)(b) and (c) GDPR, as such processing is necessary for the performance of the contract and for compliance with legal obligations.
Recipients / categories of recipients to whom the data may be disclosed
Responsible internal administrators (bookkeeping, accounting, contracts department, project management, telecommunications and IT).
External clients (GIZ, KfW, Ministries, EU, World Bank and other development banks, etc.).
For staff management: any internal department involved in carrying out respective business processes (project management and administrative departments).
Public authorities on the basis of statutory regulations (social insurance carriers, tax authorities, health insurance companies); bank institutions (for salary transactions); creditors (in the case of wage / salary garnishment); travel agencies.
Standard periods for the deletion of data
Personal data is deleted on a regular basis when it is no longer required for the performance of a contract, provided that the data subject has not separately consented to further storage and that statutory retention obligations or retention periods do not require longer storage.
Planned transfer of data to third countries
As a general rule, personal data is not transferred electronically to third countries. Exceptions may apply where there is a specific legal basis for such a transfer.
Your rights
You may at any time request access to your personal data (Article 15 GDPR) and request the rectification or erasure of your personal data (Articles 16 and 17 GDPR). You may also request restriction of processing of your personal data (Articles 18 and 19 GDPR), request data portability (Article 20 GDPR), or object to the processing of your personal data (Article 21 GDPR).
If you wish to exercise any of these rights, please send an e-mail to: datenschutz[at]gfa-holding.de. We will take the necessary measures as quickly as possible.
You also have the right to lodge a complaint with a data protection supervisory authority. The competent supervisory authority is, in particular, the Data Protection Authority of the Free and Hanseatic City of Hamburg.
Data privacy regarding the use of web analytics service Matomo
We use Matomo to analyse website usage statistics and to improve our website. Matomo is only used if you have given your prior consent.
The legal basis for storing/reading information on your device is Section 25(1) of the TTDSG; the legal basis for the subsequent processing of personal data is Article 6(1)(a) of the GDPR.
You can withdraw your consent at any time via “Cookie Settings” with effect for the future.
In doing so, your IP address will be truncated/anonymised (IP masking), provided this is technically enabled.
Data privacy regarding the use of LinkedIn
Our website uses functions from the LinkedIn network. The provider of that service is the LinkedIn Corporation, 2029 Stierlin Court, Mountain View, CA 94043, USA. Each time a page of this website containing a LinkedIn function is called up, a connection is established with the LinkedIn servers. LinkedIn is informed that you have visited our website using your IP address. If you click the Recommend button from LinkedIn and are logged in to your LinkedIn account, LinkedIn is able to assign your visit to our website to your user account. Please note that GFA, as the provider of this site, has no knowledge of the content of the data thus transmitted to or used by LinkedIn. Additional information can be found in the LinkedIn data privacy statement:
https://www.linkedin.com/legal/privacy-policy
Server log files
The provider of this website automatically collects and stores information in so-called server log files which your browser automatically transmits to us. This information includes:
- Browser type/ browser version
- Operating system being used
- Referrer URL
- Host name of accessing computer
- Time of server request
The data thus collected cannot be connected to a specific person. The data is not merged or compared with data from other sources. We reserve the right to subsequently examine this data if concrete evidence of unlawful use is made known to us.
Cookies
This website uses cookies in some cases. Cookies do not cause any damage to your computer and do not contain viruses. Cookies serve to make our website more user-friendly, effective and secure. Cookies are small text files that are stored on your computer and saved by your browser.
Most of the cookies we use are so-called ‘session cookies’. These session cookies are automatically deleted at the end of your visit. Other cookies are stored on your computer (device) until you delete them. These cookies enable us to recognise your browser the next time you visit our website.
You can configure your browser so that you are informed about the use of cookies, so that you can accept them on a case-by-case basis, so that you can prohibit the use of cookies in certain cases, or so that you can block cookies generally or have them deleted automatically when you close your browser.
Disabling cookies may restrict the functionality of this website.
Contact form
When you send us an enquiry via the contact form, we will store the details you provide in the enquiry form, including your contact details, so that we can process your enquiry and in case of any follow-up enquiries. We will only pass on your data where this is necessary for processing the enquiry (e.g. to IT service providers) or where there is a legal basis for doing so.
Objection to unsolicited advertising
The use of the contact information included in the Legal Notice to send unsolicited advertising and informational materials is herewith prohibited. The operators of this website expressly reserve the right to take legal steps in the event that unsolicited advertising materials are sent, specifically through spam e-mail.
Service Provider
The content of our website is hosted with the following provider:
RAIDBOXES
The provider is RAIDBOXES GmbH, Hafenstr. 32, 48151 Münster, Germany (hereinafter referred to as “RAIDBOXES”). When you visit our website, RAIDBOXES collects various log files, including your IP address.
For further details, please refer to the RAIDBOXES Privacy Policy:
https://raidboxes.io/legal/privacy/
The use of RAIDBOXES is based on Article 6(1)(f) GDPR. We have a legitimate interest in ensuring that our website is displayed as reliably as possible. Where consent has been requested, processing is carried out exclusively on the basis of Article 6(1)(a) GDPR and Section 25(1) TDDDG, insofar as the consent includes the storage of cookies or access to information on the user’s terminal device, for example for device fingerprinting, within the meaning of the TDDDG. Consent may be withdrawn at any time.
Data Processing Agreement
We have concluded a Data Processing Agreement (DPA) for the use of the above-mentioned service. This is a contract required under data protection law which ensures that the provider processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.