Privacy Policy


Privacy Policy

General

1.Your personal data within the meaning of Art. 4 No. 1 GDPR (e.g. IP address, email address, name) is processed by us only in accordance with the provisions of German data protection law and taking into account the European

General Data Protection Regulation (GDPR). The following provisions inform you about the nature, scope, and purpose of the collection, processing, and use of personal data.

2.The processing within the meaning of Art. 4 No. 2 GDPR of personal data is lawful pursuant to Art. 6 GDPR if one of the following conditions is met:
  • a.The data subject has given consent to the processing of their personal data for one or more specific purposes;
  • b.processing is necessary for the performance of a contract to which the data subject is party, or in order to take steps at the request of the data subject prior to entering into a contract;
  • c.processing is necessary for compliance with a legal obligation to which the controller is subject;
  • d.processing is necessary in order to protect the vital interests of the data subject or of another natural person;
  • e.processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
  • f.processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.
3. The processing of special categories of personal data within the meaning of Art. 9 Para. 1 GDPR is lawful in particular pursuant to Art. 9 Para. 2 GDPR if one of the following conditions is met:
  • the data subject has given explicit consent;
  • processing is necessary for the establishment, exercise, or defence of legal claims or whenever courts are acting in their judicial capacity.
4.Automated individual decision-making or profiling regarding personal data within the meaning of Art. 22 GDPR does not take place.
5.The operator ensures the security of data in accordance with Art. 32 GDPR, taking into account the principle of proportionality, through appropriate technical measures.
6.Should a data protection breach unexpectedly occur, the competent supervisory authority will be notified in accordance with Art. 33 GDPR, and the data subject will be notified in accordance with Art. 34 GDPR.

Scope of Application

This privacy policy applies only to our websites. If you are redirected to other websites via links on our pages, please refer to those sites for information on how they handle your data.

Data Retention Period

The retention period of the data you have transmitted is governed by statutory retention obligations. Where commercial and tax law retention periods apply, the storage duration of certain data may be up to 10 years.

Sharing Data with Third Parties

Data transmitted in the course of making contact will only be passed on to third parties (Art. 4 No. 10 GDPR) if:

  1. You have given your express consent pursuant to Art. 6 Para. 1 S. 1 lit. a GDPR.
  2. The transfer pursuant to Art. 6 Para. 1 S. 1 lit. f GDPR is necessary for the establishment, exercise, or defence of legal claims and there is no reason to assume that you have an overriding legitimate interest in not having your data disclosed.
  3. In the event that there is a legal obligation to transfer pursuant to Art. 6 Para. 1 S. 1 lit. c GDPR, as well as
  4. This is legally permissible and required pursuant to Art. 6 Para. 1 S. 1 lit. b GDPR for the processing of contractual relationships with you.

Controller within the Meaning of the GDPR

The controller within the meaning of the General Data Protection Regulation (GDPR), as well as other data protection laws applicable in the European Union and other provisions of a data protection nature, is:

Garten Eden

Beluga GmbH

Weyerstraße 54a

50676 Cologne

Phone: 0221 98860551

Email: info@garteneden-koeln.de

Storage of Access Data in Log Files

You can visit our websites without providing any personal information.

We only store access data in so-called server log files, such as the name of the requested file, date and time of access, amount of data transferred, and the requesting provider.

This data is evaluated exclusively to ensure smooth operation of the site and to improve our offering, and does not allow us to draw any conclusions about you personally.

The purpose of processing arises from our legitimate interest within the meaning of Art. 6 Para. 1 S. 1 lit. f) GDPR.

A data processing agreement has been concluded with our hosting provider.

Google Web Fonts

This website uses external fonts, Google Fonts.

Google Fonts is a service provided by Google Inc. ("Google").

The integration of these web fonts is carried out by a server call, usually a server of Google in the USA.

This transmits to the server which of our web pages you have visited.

The IP address of the browser of the visitor's device is also stored by Google.

For more information, please refer to Google's privacy notices, which you can access here:

Google Maps

This website uses the "Google Maps API" of Google Inc. (Google) for the visual display of map material.

When using Google Maps, data about the use of the Maps functions by visitors to the websites is also collected, processed, and used by Google.

The terms of use for Google Maps can be found under Google Maps Terms of Use.

For more information on Google's privacy policies, please visit:

Contact Form

When using the contact form offered on these pages, the information you enter and any attached files will be transmitted and stored for the purpose of responding to your inquiry.

Data transmitted in the course of making contact will only be passed on to third parties if you have expressly given your consent.

The lawfulness of using the contact form arises from Art. 6 Para. 1 S. 1 lit. f) GDPR.

Social Media Links

We maintain our own social media pages accessible via links from this website.

By using the links, you will be directed to the respective websites of third-party providers (e.g. Facebook, YouTube) and can also share our content.

No data transfer takes place when you access our website.

Once you have accessed the third-party provider's page, you are within the responsibility of that provider, so their privacy policy or data usage statements apply.

We have no influence over this; however, to avoid unnecessary data sharing, we recommend logging out of the respective third-party provider before using a corresponding link, so that usage profiles cannot be created by the provider merely through the use of the link.

Applications

During the application process, personal data such as name, address, telephone number, and email address are stored in the applicant database.

Furthermore, application documents (cover letter, CV, certificates, etc.) are recorded and stored.

Your data will be evaluated, processed, or forwarded internally exclusively within the scope of the application process.

Applicant data can only be viewed by HR staff and the persons responsible for selection.

No data is passed on to third parties in any way.

In the event of a successful application, the application data will be transferred to the personnel file.

All other applicant data will be stored for a maximum of 3 months after the end of the application process.

You have the right to withdraw your consent and request the deletion of your applicant data at any time. An informal email to us is sufficient for this purpose.

Security of Your Data / SSL Encryption

In accordance with the statutory provision of Section 13 Para. 7 TMG, this site uses SSL encryption, recognizable by a padlock icon in the address bar of your browser.

Transmitted data cannot be read by third parties when SSL encryption is active.

This is generally 256-bit encryption.

If your browser does not support 256-bit encryption, we use 128-bit v3 technology instead.

Whether an individual page of our website is transmitted in encrypted form can be identified by the closed display of the key or padlock symbol in the lower status bar of your browser.

We also use appropriate technical and organizational security measures (TOMs) to protect your data against accidental or intentional manipulation, partial or complete loss, destruction, or unauthorized access by third parties.

Our security measures are continuously improved in line with technological developments.

User Rights

You may request information about the personal data stored about you at any time and free of charge. Your rights also include confirmation, correction, restriction, blocking, and deletion of such data, the provision of a copy of the data in a format suitable for transfer, the withdrawal of given consent, and the right to object. Statutory retention obligations remain unaffected.

Your rights arise in particular from the following provisions of the GDPR:

  • Article 7 Para. 3 – Right to withdraw a data protection consent
  • Article 12 – Transparent information, communication, and modalities for the exercise of the rights of the data subject
  • Article 13 – Information to be provided where personal data are collected from the data subject
  • Article 14 – Information to be provided where personal data have not been obtained from the data subject
  • Article 15 – Right of access by the data subject, right to confirmation, and provision of a copy of personal data
  • Article 16 – Right to rectification
  • Article 17 – Right to erasure ('right to be forgotten')
  • Article 18 – Right to restriction of processing
  • Article 19 – Notification obligation regarding rectification or erasure of personal data or restriction of processing
  • Article 20 – Right to data portability
  • Article 21 – Right to object
  • Article 22 – Right not to be subject to a decision based solely on automated processing, including profiling
  • Article 77 – Right to lodge a complaint with a supervisory authority

To exercise your rights (with the exception of Art. 77 GDPR), please contact the entity mentioned under 'Controller within the Meaning of the GDPR' (e.g. by email).

Competent Supervisory Authority

State Commissioner for Data Protection and Freedom of Information NRW

Kavalleriestr. 2-4

40213 Düsseldorf

Phone: 0211/38424-0Fax: 0211/38424-10E-Mail: poststelle@ldi.nrw.de

Please check the above homepage before making contact to verify that the contact details are still current.