HecknerGroup

Privacy policy

Information on the processing of personal data pursuant to Art. 13 and 14 GDPR.

This English version is a translation provided for convenience. The legally binding version is the German one; in case of any discrepancy, the German text prevails. German version

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

HecknerGroup GmbH
Alte Regensburger Straße 26
84030 Ergolding
Germany
Represented by: Jürgen Heckner
Email: office@hecknergroup.de
Phone: +49 871 96 69 09 99

2. General information

This privacy policy provides information on the nature, scope and purpose of the processing of personal data when you visit this website. Personal data means any information relating to an identified or identifiable natural person.

As a rule we process personal data only to the extent necessary to provide a functioning website and our content. The legal bases are in particular Art. 6(1)(b) GDPR (contract and pre-contractual steps), Art. 6(1)(f) GDPR (legitimate interest) and Art. 6(1)(a) GDPR (consent), where consent is obtained.

3. Hosting

This website runs on a server we rent from an external service provider (processor):

Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany.

For our mailboxes we use Microsoft 365 (Microsoft Ireland Operations Limited, Dublin). Form submissions on this website are also sent through Microsoft 365 – see section 8.

The server is located in a data centre in Nuremberg, Germany. No personal data is transferred to a third country outside the EU or the EEA in this context.

On our behalf the provider processes, among other things, access data and server log files (see section 4). The legal basis is our legitimate interest in providing our online offering securely and efficiently (Art. 6(1)(f) GDPR).

4. Server log files

When you access this website, information transmitted by your browser is recorded automatically. This comprises:

  • anonymised or shortened IP address
  • date and time of access
  • page or file accessed
  • browser type and version, and operating system
  • referrer URL

This data is processed in order to deliver the website, to ensure the security and stability of the system, and for error analysis (Art. 6(1)(f) GDPR). It is not combined with other data sources and not used for advertising purposes.

5. Cookies & tracking

This website uses no tracking, analytics or marketing cookies and includes no services for measuring reach. No profiling takes place.

6. Fonts (hosted locally)

We use fonts that are provided locally from our own server (self-hosted, via next/font). When the website is accessed, no connection is made to third-party servers (Google Fonts, for example); no data is transmitted to third parties for this purpose.

7. Video content (hosted locally)

A background video is shown on the home page. It is delivered directly from our own server and not embedded via third-party providers such as YouTube or Vimeo. No data is therefore transmitted to third parties.

8. Getting in touch and forms

If you contact us by email or telephone, the data you provide (name, contact details, content of the enquiry, for example) is processed in order to handle your request. The legal basis is Art. 6(1)(b) GDPR (pre-contractual steps and contract) or Art. 6(1)(f) GDPR (interest in answering your enquiry). The data is deleted as soon as it is no longer required for that purpose and no statutory retention obligations stand in the way.

Contact and crisis form. On the “Contact” and “Emergency support” pages you can reach us through a form. We process the details you enter there: company, name, phone number, the category you chose for your enquiry and your message. We deliberately do not ask for an email address – we call you back.

What happens to the message. The details are not stored on the website but transmitted solely by email to our mailbox and handled there. There is no database and no automatic acknowledgement of receipt. The time of receipt and your IP address are sent with it; they serve traceability in the event of misuse (Art. 6(1)(f) GDPR) and are deleted together with the message.

Protection against automated submissions. So that the form is not misused by machines, we check every submission several times over: with an additional field invisible to you, with a signed timestamp, with a limit on submissions per IP address, and with a computing task that your browser solves in the background (ALTCHA). All of these checks run on our own server. No third-party service is involved, no script is loaded from external servers, and no cookie is set.

Recipients. We operate our mailboxes with Microsoft 365. Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland, therefore acts as a processor for sending, receiving and retaining the form messages. Processing takes place in data centres within the European Union. Beyond that we do not pass your details on.

9. Job applications

You can send us a message through the form on the careers page. The data entered there is processed (name, email address, optionally a telephone number and a link to a profile or portfolio, and the content of your message). The legal basis is § 26(1) BDSG (German Federal Data Protection Act) in conjunction with Art. 6(1)(b) GDPR (establishing an employment relationship).

The message is transmitted solely by email to the management and handled there. No application data is stored on this website, and no upload of documents is provided for. If required, we request application documents by email at a later stage.

If no employment relationship is established, we delete your details six months after the procedure has concluded. This period serves to defend against possible claims under the German General Equal Treatment Act (AGG). If you agree to longer retention, for future opportunities for instance, we will ask you separately.

10. Link to our LinkedIn profile

In the footer of this website we link to our company page on LinkedIn. This is a plain link, not an embedded social media plugin: when our page is accessed, no data is transmitted to LinkedIn, nothing is loaded from there, and no cookie is set. Data is only transmitted once you actively click the link.

LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland, is responsible for the processing of data on the linked platform. We have no influence over it.

11. Your rights

Under the GDPR you have in particular the following rights:

  • access to the data processed (Art. 15 GDPR)
  • rectification of inaccurate data (Art. 16 GDPR)
  • erasure (Art. 17 GDPR)
  • restriction of processing (Art. 18 GDPR)
  • data portability (Art. 20 GDPR)
  • objection to processing (Art. 21 GDPR)
  • withdrawal of consent given (Art. 7(3) GDPR)

To exercise your rights, a message to the contact details given above is sufficient.

12. Right to lodge a complaint with a supervisory authority

You have the right to lodge a complaint with a data protection supervisory authority. The competent authority is the one at our company's registered office:

Bayerisches Landesamt für Datenschutzaufsicht (BayLDA – the Bavarian data protection supervisory authority), Promenade 18, 91522 Ansbach, Germany.

13. Validity and amendment of this privacy policy

This privacy policy is currently valid. As our website develops further, or because of changed statutory or regulatory requirements, it may become necessary to amend it.