Privacy statement

Table of content

We process personal data only to the extent necessary for the respective purpose and where a legal basis exists.

Personal data means any information relating to an identified or identifiable natural person. This includes, for example, names, contact details, IP addresses, communication content or other information transmitted when using our website or contacting us.

The specific purposes of the processing, the data processed in each case, the legal bases, potential recipients and retention periods are described in the following sections.

§ 1 Name and address of the controller

The controller responsible for the processing of personal data within the meaning of the General Data Protection Regulation (GDPR) is:
ABS-Ingenieurdienstleistung GmbH
Annaröder Straße 11
06313 Ahlsdorf
E-Mail: info@abs-id.de

§ 2 Legal basis of the processing

We process personal data only where a legal basis exists. The legal basis applicable in each individual case is explained for the respective processing operation in the following sections.

Depending on the processing operation, the following legal bases may apply in particular:

Where special categories of personal data are processed, this takes place only if an additional condition under Art. 9 (2) GDPR is met.

Where processing is based on consent, that consent may be withdrawn at any time with effect for the future. The lawfulness of processing carried out before the withdrawal remains unaffected.

§ 3 Duration of storage of personal data

We store personal data only for as long as necessary for the respective processing purpose. We may also store data where statutory retention obligations apply or where further storage is necessary for the establishment, exercise or defence of legal claims.

The specific retention period or the criteria used to determine it are specified for the respective processing operation in the following sections. Where no specific retention period can be stated, we take into account in particular:

Once the processing purpose no longer applies and there is no legal basis for continued storage, the personal data is deleted or anonymised. Where statutory retention obligations apply, processing is restricted to compliance with those obligations for the duration of the retention period.

§ 4 Rights of data subjects

Subject to the applicable legal requirements, you have the following rights:

To exercise your rights, you may contact us or our data protection officer at any time. Where we have reasonable doubts concerning your identity, we may request additional information necessary to confirm your identity.

You may lodge a complaint in particular with a supervisory authority in the Member State of your habitual residence, place of work or place of the alleged infringement.
The supervisory authority responsible for us is:
Landesbeauftragte für den Datenschutz
Geschäftsstelle und Besucheradresse: Otto-von-Guericke-Straße 34a, 39104 Magdeburg
Postadresse: Postfach 1947, 39009 Magdeburg
Telefon: 0391 81803-0
E-Mail: poststelle@lfd.sachsen-anhalt.de
https://datenschutz.sachsen-anhalt.de/

§ 5 Legitimate interests in the processing pursued by the controller or by a third party

Where we base processing on Art. 6 (1) f GDPR, we specify for the respective processing activity the legitimate interests pursued by us or by a third party.

Before processing, we assess whether it is necessary for the purposes of those interests and balance our interests or those of a third party against your interests, fundamental rights and freedoms. Particular consideration is given to the rights and interests of children.

§ 6 Right to object

Where we process personal data on the basis of Art. 6 (1) e or f GDPR, you have the right to object to this processing at any time on grounds relating to your particular situation. This also applies to profiling based on these provisions.

We will then no longer process the personal data concerned unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.

Where personal data are processed for direct marketing purposes, you may object to this processing at any time. This also applies to profiling to the extent that it is related to such direct marketing. Following your objection, your personal data will no longer be processed for these purposes.

Where processing is based on your consent, there is no right to object in the above sense. Instead, you may withdraw your consent at any time with effect for the future.

§ 7 Requirement to provide personal data

For individual processing activities, the provision of certain personal data may be required by law or contract or may be necessary to enter into or perform a contract, process an enquiry or registration, perform a statutory, public or ecclesiastical task, or provide a function requested by you.

The information required for the respective processing activity is indicated in the relevant input form or in the description of the processing activity in this privacy statement. Where possible, required information is identified as mandatory.

If required data are not provided, we may be unable to process an enquiry or registration, enter into or perform a contract, provide a service or perform a statutory task. The specific consequences are explained in connection with the respective processing activity. Information that is not required may be provided voluntarily. You will not suffer any disadvantage if you do not provide voluntary information.

If you have questions about whether particular information is required, you may contact the controller or, where appointed, the data protection officer using the contact details provided at the beginning of this privacy statement.

§ 8 Provision of the website and hosting

We use hosting services provided by Hetzner Online GmbH to make this website available and operate it securely. When you access our website, the hosting provider processes technically necessary personal data on our behalf. This may include in particular your IP address, the date and time of access, the page or file requested, the amount of data transferred, the previously visited page, information about the browser and operating system used, and technical connection and security data.

The processing is carried out to deliver the website, ensure its functionality and stability, detect technical errors, and prevent attacks or misuse. The legal basis is Art. 6 (1) f GDPR. Our legitimate interest lies in the secure, stable and functional operation of our website.

The hosting provider processes personal data as a processor. The processing is carried out on the basis of a data processing agreement pursuant to Art. 28 GDPR.

Server log data generated when the website is accessed are stored for 30 days and then deleted or anonymised, unless longer storage is necessary to investigate a specific security incident. Further details on the processing of server log files can be found in the section "Server log files".

Hetzner Online GmbH
Industriestrasse 25
91710 Gunzenhausen
Germany

Further information on data protection at the hosting provider can be found at: https://www.hetzner.com/legal/privacy-policy/.

§ 9 Transfers to third countries

Where we transfer personal data to recipients outside the European Union or the European Economic Area, we do so only in accordance with the statutory requirements of Arts. 44 to 49 GDPR.

A transfer may be based in particular on an adequacy decision of the European Commission pursuant to Art. 45 GDPR or on appropriate safeguards pursuant to Art. 46 GDPR. Appropriate safeguards include in particular Standard Contractual Clauses adopted by the European Commission or Binding Corporate Rules. Where necessary, supplementary safeguards are agreed. In exceptional cases provided for by law, a transfer may be based on Art. 49 GDPR.

For transfers to the United States, the adequacy decision concerning the EU-U.S. Data Privacy Framework may be used where the respective US recipient is certified for the relevant data categories. The former EU-US Privacy Shield is not used as a basis for data transfers.

Whether a transfer to a third country takes place and the basis on which it is made are explained in more detail for the respective processing activity.

§ 10 Cookies and comparable technologies

Our website uses cookies and comparable technologies. Cookies are small text files stored on your device. Comparable technologies include Local Storage, Session Storage and other methods of storing information on or accessing information from your device. Session entries are generally deleted at the end of the session; persistent entries remain until their respective retention period expires or until they are deleted.

Consent is not required under Sec. 25 (2) no. 2 TDDDG where storing or accessing information is strictly necessary to provide a digital service expressly requested by you. In these cases, the subsequent processing of personal data is based on Art. 6 (1) f GDPR. Our legitimate interest lies in the secure and functional operation of the website and the provision of the functions requested by you.

Cookies and comparable technologies that are not strictly necessary are used only after you have given your prior consent. The legal basis for storing or accessing information on your device is Sec. 25 (1) TDDDG. The subsequent processing of personal data is based on Art. 6 (1) a GDPR. This applies in particular to technologies used for analytics, audience measurement, marketing or the integration of non-essential external content.

You may withdraw or change your consent pursuant to Art. 7 (3) GDPR at any time with effect for the future using the privacy or cookie settings provided on our website. The lawfulness of processing carried out before the withdrawal remains unaffected.

You can also delete cookies and comparable stored information or restrict their storage through your browser settings. This may impair individual functions of the website. Preventing or deleting cookies in the browser does not replace the withdrawal of consent already given.

Further information on the technologies actually used, their providers, purposes and retention periods can be found in the information on the respective services and, where a consent management facility is provided, in its privacy settings.

§ 11 Server log files

When our website is accessed, server log files are processed automatically. The data collected may include in particular the IP address, date and time of access, the URL requested, the HTTP status code, the amount of data transferred, the previously visited page, browser type and version, the operating system used, and technical connection data. As long as the IP address permits a person to be identified, the data are not collected anonymously.

The processing is carried out to make the website technically available, ensure its stability and security, detect errors, and prevent misuse or attacks. The legal basis is Art. 6 (1) f GDPR. Our legitimate interest lies in the secure, stable and functional operation of our website.

The server log files are stored for 30 days and then deleted or anonymised so that they can no longer be linked to an individual. Personal data are retained for longer only where this is necessary to investigate or document a specific security incident. In that case, the data concerned are deleted or anonymised as soon as they are no longer required for this purpose.

As a rule, server log files are not combined with other data sources. They may be analysed or combined in an individual case where there are specific indications of a security incident or misuse.

§ 12 Contact by email

If you contact us by email, we process the personal data you provide in order to handle your request and communicate with you. This may include in particular your name, email address, any telephone number provided, the content of your message, attached documents, and the date and time of the communication.

If your request relates to a contract, registration or pre-contractual measures, the processing is based on Art. 6 (1) b GDPR. For other requests, the legal basis is Art. 6 (1) f GDPR. Our legitimate interest lies in properly handling and responding to incoming requests. Where processing is necessary to comply with a legal obligation, it is based on Art. 6 (1) c GDPR. Where it takes place in the context of a public or ecclesiastical task entrusted to us, Art. 6 (1) e GDPR may apply.

Recipients of the data are the internal departments responsible for handling your request. IT and email service providers used by us may also have access to the data. Where these service providers process personal data on our behalf, this is done on the basis of a data processing agreement pursuant to Art. 28 GDPR.

We delete data processed in connection with your request as soon as the request has been finally dealt with and there are no statutory retention obligations or other legal grounds for further storage. Where data are required to comply with retention obligations or to establish, exercise or defend legal claims, they are retained for those purposes and subsequently deleted.

§ 13 Contact form

If you use a contact form provided on our website, we process the data you enter in order to handle your request and communicate with you. The data processed are shown in the respective input form. They may include in particular your name, email address, telephone number and the content of your message. The date and time of transmission and technical data required for secure transmission may also be processed.

Information marked as mandatory in the respective form is required to process your request. Without this information, we may not be able to process the request. Information not marked as mandatory is voluntary.

If your request relates to a contract, registration or pre-contractual measures, the processing is based on Art. 6 (1) b GDPR. For other requests, the legal basis is Art. 6 (1) f GDPR. Our legitimate interest lies in properly handling and responding to incoming requests. Where processing is necessary to comply with a legal obligation, it is based on Art. 6 (1) c GDPR. Where it takes place in the context of a public or ecclesiastical task entrusted to us, Art. 6 (1) e GDPR may apply.

Data submitted through the contact form are forwarded to the internal departments responsible for handling the request. Hosting, IT and email service providers used by us may also have access to the data. Where these service providers process personal data on our behalf, this is done on the basis of a data processing agreement pursuant to Art. 28 GDPR.

We delete data processed in connection with your request as soon as the request has been finally dealt with and there are no statutory retention obligations or other legal grounds for further storage. Where data are required to comply with retention obligations or to establish, exercise or defend legal claims, they are retained for those purposes and subsequently deleted.

§ 14 Applications and application procedures

If you apply for a position with us, we process the personal data you submit in order to conduct the application procedure. This may include in particular your name and contact details, cover letter, curriculum vitae, references, proof of qualifications, information about your professional background, communication data and other information provided by you.

We process the data in order to assess your application, communicate with you and decide whether to establish an employment relationship. The legal basis is Art. 6 (1) b GDPR in conjunction with Sec. 26 (1) BDSG. Without the information required to assess your application, we cannot conduct the application procedure.

Where special categories of personal data required for the application procedure are processed, the legal basis is Art. 9 (2) b GDPR in conjunction with Sec. 26 (3) BDSG. Please provide us with special categories of personal data only where this is necessary for the application procedure.

Access to application data is restricted to the persons and internal departments involved in the application procedure. These may include in particular human resources, the management of the company, institution or school, the responsible specialist department and, where applicable, the competent employee representative body. Hosting, IT or recruitment service providers used by us may also have access. Where these service providers process personal data on our behalf, this is done on the basis of a data processing agreement pursuant to Art. 28 GDPR.

If an employment relationship is established, the application data required for this purpose are transferred to the personnel file and processed further for the performance of the employment relationship.

If no employment relationship is established, we generally delete the application data six months after completion of the application procedure or receipt of the rejection. The temporary continued retention is based on Art. 6 (1) f GDPR. Our legitimate interest lies in the establishment, exercise or defence of legal claims, in particular under the German General Act on Equal Treatment. Where claims are asserted, the data required for this purpose may be retained until the proceedings have been finally concluded.

We retain your data for consideration in future recruitment procedures only with your consent on the basis of Art. 6 (1) a GDPR. We inform you of the specific retention period when obtaining your consent. You may withdraw your consent pursuant to Art. 7 (3) GDPR at any time with effect for the future. The lawfulness of processing carried out before withdrawal remains unaffected.

§ 15 Privacy policy on the use and application of Matomo

The responsible person has integrated the component Matomo in this application. Matomo is an open source software tool for usage analysis. Usage analysis is the collection and analysis of data about user behavior on applications. In the web the tool records from which website the user has accessed this website, which subpages have been accessed and how often and how long subpages have been viewed by the user. In a mobile app the tool records time spent in the application and user interactions. This analysis is used to optimize the application.

The software is operated on the server of the responsible person. All log files are stored exclusively on this server.

The legal basis for processing data is the legitimate interest of the controller to optimise and evaluate the use of the application (Art. 6 par. 1 (f) GDPR). A weighing of interests of the controller and of the data subject has been carried out.

Matomo places a cookie on the IT system of the user concerned. The cookie enables the analysis of usage. Each time one of the individual pages is called up, the Internet browser on the IT system of the person concerned is automatically prompted to transmit data to our server for the purpose of online analysis. In this process, we obtain knowledge of the IP address of the person concerned, which serves, among other things, to trace the origin of the visitors. In addition to the IP address, the access time, location from which the access originated and the frequency of visits to our website are stored. The IP address is made anonymous immediately upon collection.

By adjusting the settings of the Internet browser used, the setting of cookies by Matomo can be permanently rejected. In addition, set cookies can be deleted at any time via the Internet browser or other software. Furthermore, it is possible to object to the recording of the use by Matomo. The person concerned must set an opt-out cookie for this purpose. If the cookie settings of the Internet browser used are reset, this cookie would have to be set again.

The setting of the opt-out cookie may lead to restrictions in the functionality of the website.

Further information and Matomo's current data protection regulations can be found at https://matomo.org/privacy/ abgerufen werden.

§ 16 Error analysis and technical error logging

We use Sentry-compatible error logging to detect, analyse and resolve technical errors. The processing serves to ensure the technical functionality of our website, resolve errors and improve the stability of our systems.

The data processed may include in particular the IP address, date and time of the error, the URL accessed, browser and device information, the operating system, the error message, technical session data and information about the function affected. The data generated in an individual case depend on the type of error and the function affected.

The legal basis is Art. 6 (1) f GDPR. Our legitimate interest lies in the secure, stable and as error-free as possible operation of our website and the functions provided through it.

The error data are processed within the technical infrastructure used by us. Access is granted to the internal departments responsible for error analysis and, where necessary, to hosting and IT service providers used by us. Where these service providers process personal data on our behalf, this is done on the basis of a data processing agreement pursuant to Art. 28 GDPR.

The error data are stored for 90 days and then deleted. They are stored for longer only where this is necessary to investigate or resolve a specific technical or security-related incident. After the matter has been resolved, the data are deleted unless statutory retention obligations or other legal grounds require further storage.

The error data are not used for advertising purposes or to create user profiles.

§ 17 Integration of Google reCAPTCHA

We use Google reCAPTCHA v2 to protect our forms against spam, automated attacks and misuse. The service analyses whether an entry is made by a natural person or by automated means.

The contractual provider and processor is Google Cloud EMEA Limited, based in Dublin, Ireland. The data processed may include in particular the IP address, browser and device information, operating system, date and time of access, the page accessed, and mouse, keyboard and other interaction data. reCAPTCHA also uses cookies or comparable technologies, in particular _GRECAPTCHA, for risk analysis and abuse prevention.

Where reCAPTCHA stores information on your device or accesses information stored there, this is based on Sec. 25 (2) no. 2 TDDDG. The access is necessary to provide securely the form function expressly requested by you and to protect it against automated misuse.

The legal basis for processing personal data is Art. 6 (1) f GDPR. Our legitimate interest lies in preventing spam and misuse and ensuring the IT security of our forms. You may object to this processing on grounds relating to your particular situation pursuant to Art. 21 GDPR.

Since 2 April 2026, Google processes reCAPTCHA Customer Data as a processor in accordance with the Google Cloud Terms of Service and the Google Cloud Data Processing Addendum. The processing on behalf is governed by Art. 28 GDPR.

Processing may take place in third countries, in particular the United States. Google LLC is certified under the EU-U.S. Data Privacy Framework for covered data categories. Where a transfer is not covered by the associated adequacy decision, Google uses in particular Standard Contractual Clauses adopted by the European Commission in accordance with the Google Cloud contractual terms.

We process the verification result provided by reCAPTCHA only for as long as necessary to verify and secure the respective form submission. Further processing and deletion of Customer Data processed by Google are governed by the Google Cloud contractual terms and the Data Processing Addendum.

Further information is available in the Google reCAPTCHA information and the Google Cloud Data Processing Addendum.

§ 18 Status of and amendments to this privacy notice

We review this privacy notice regularly and amend it where the processing activities we carry out change or where legal, technical or organisational developments make an amendment necessary.

The version of this privacy notice published on this website at the relevant time applies.