Data Protection Information for Customers of KEB Hana Bank (D) AG
1. Content
With this data protection information, we inform you, our customers, in accordance with the European General Data Protection Regulation (GDPR) and the Federal Data Protection Act (BDSG), about the processing of your personal data by us as well as about your rights. These notices will be updated as necessary and published at www.kebhana.de/datenschutz.
If you are not yourself our customer but an representative of the customer (for example, board member, managing director), employee, or beneficial owner of our customer, these data protection notices apply to you as well.
Which data are processed in detail and how they are used depends on the respective agreed services.
Please also pass on this data protection information to authorized representatives, employees, beneficial owners, or agents.
2. Controller and Contact
The controller is us, your employer,
KEB Hana Bank (D) AG
Bockenheimer Landstr. 33–35
60325 Frankfurt/Main
Telephone: +49 69 7129-0
info (at) kebhana.de
The contact details of our Data Protection Officer are:
thomas.helbing (at) datenschutz-helbing.de
This data protection information also apply to our legally dependent branches, for example in Poland. These are part of the entity mentioned above and are not independent controllers within the meaning of the GDPR.
3. Categories of Data
We process data that we receive from the business relationship with you. We receive the data directly from you or from the customer, for example in the context of account opening, contract initiation, and conclusion of the contract.
Specifically, we process in particular the following categories of data:
3.1. Master data: Basic information about you, such as name, address and contact details, bank account, occupation, marital status, your role or function with the customer, any status as a politically exposed person (PEP)
3.2. Identification data: Data processed for the purpose of identifying you (for example, personal details to be collected for identification purposes as well as ID data and unique identifiers such as tax numbers or national identification numbers)
3.3. Transaction data: Data in connection with the execution of contracts between us and the customer (for example, orders), including payment transaction and trade finance data (SWIFT/SEPA/TARGET, letters of credit, collections, forfaiting), interbank/correspondent banking data
3.4. Tax data: Tax-relevant data (for example, for withholding tax and exemption orders, non-assessment data, church tax deduction feature)
3.5. Contract data relating to other products: Contract data, for example relating to concluded credit agreements
3.6. Correspondence data: Data from correspondence with you (for example, written communication with you)
3.7. Marketing and sales data: Data relating to marketing activities by us towards you (for example, products that may be of interest to you)
3.8. Technical data (if used): Log files, access logs, IP addresses, device identifiers, session data, and other IT security-related information.
4. Obligation to Provide Data
Within our business relationship, you are only required to provide those personal data that are necessary for the establishment, performance, and termination of a business relationship with the customer or which we are legally obliged to collect.
Without these data, we will generally be unable to conclude the contract or execute the order due to lack of feasibility or to continue an existing contract and may have to terminate it. In particular, under the provisions of anti-money laundering law, we are obliged to identify you prior to establishing the business relationship, for example on the basis of your identity card, and to collect your name, place of birth, date of birth, nationality, and residential address. To enable us to comply with this legal obligation, you must provide us with the necessary information and documents under the Money Laundering Act and promptly notify us of any changes arising during the course of the business relationship. If you do not provide us with the required information and documents, we may not establish or continue the business relationship you request.
5. Sources of Data
We receive the data directly from you or from the customer or from your contractual partners or correspondent banks.
Where permissible, we may also obtain data from public sources (for example, land registers, commercial and association registers, press, media, internet), from credit agencies, business information services, and public authorities (for example, residents’ registration offices) or from our parent company, Hana Bank Co., Ltd. (trading as KEB Hana Bank), 35 Eulji-ro, Jung-gu, Seoul 04523, Republic of Korea (“Parent Company”).
6. Purpose of Processing and Legal Basis
We process personal data in accordance with the provisions of the GDPR and the BDSG. Below, we inform you about the purposes for which and the legal bases on which we process your data.
6.1. For the Fulfilment of Contractual Obligations (Art. 6 para. 1 lit. b GDPR)
We process your data for the performance of our contracts with our customers or for pre-contractual measures, that is in particular for account management, execution of credit agreements, trade finance processing, foreign exchange transactions, and execution of your orders as well as all activities required for the operation and administration of a credit and financial services institution.
The purposes of data processing depend in detail on the specific product and the contractual documentation.
6.2. Within the Scope of the Balancing of Interests (Art. 6 para. 1 lit. f GDPR)
We also process your data beyond the actual fulfilment of the contract on the basis of a balancing of interests to safeguard our legitimate interests or those of third parties. This takes place, each within the limits of what is legally permissible, for the following purposes:
- general business management and further development of services and products
- advertising, market and opinion research
- assertion of legal claims and defense in legal disputes and securing of relevant evidence
- prevention and investigation of criminal offenses
- ensuring IT security and IT operations
- ensuring effective and efficient compliance with statutory and regulatory provisions and demonstrating compliance
- identification, assessment, and control of risks
- prevention, detection, and termination of fraud and abuse
- preparation of analyses, reports, and evaluations for the development and improvement of our products, services, and internal processes and for business management.
The interests in the respective processing arise from the aforementioned purposes and also include:
- improvement of our internal processes as well as our services and products (for example, for better customer service)
- increase of efficiency and profitability (for example, through centralization and standardization of processes and functions within the KEB Hana Group as well as through the use of modern IT systems and specialized service providers)
- promotion of sales
- protection of assets (for example, against fraud), property, and health
- ensuring information security and data protection.
6.3. Based on Your Consent (Art. 6 para. 1 lit. a GDPR)
Where you have given us consent to process personal data, this consent constitutes the legal basis for the processing referred to therein. This applies in particular to your possible consent to receive marketing communications.
6.4. Based on Legal Obligations (Art. 6 para. 1 lit. c GDPR)
We are subject to various legal obligations, that is statutory requirements (for example, the German Banking Act (KWG), Anti-Money Laundering Act (GWG), tax laws, foreign trade law, sanctions regimes, payment system regulations) as well as supervisory requirements (for example, of the European Central Bank, European Banking Authority, Deutsche Bundesbank, and Federal Financial Supervisory Authority). The purposes of processing include identity, fraud, and money laundering prevention, prevention of terrorist financing, compliance with tax control and reporting obligations, and the assessment and management of risks.
7. Nature of Processing, Profiling
Within the scope of the aforementioned processing operations, we may, in compliance with legal requirements, also use data for the development, training, application, improvement, and monitoring of artificial intelligence models and systems. Possible areas of application include, for example, the recording and classification of data (for example, in incoming documents), the recognition of patterns and relationships in large data sets (for example, for combating fraud or in customer consulting, support, and sales), and support for process automation (for example, in customer service).
We may process your data partly automatically with the aim of evaluating certain personal aspects (so-called “profiling” according to Art. 4 No. 4 GDPR). We may use profiling, for example, in the following cases: Based on statutory, regulatory, and sanctions-related requirements in the context of combating money laundering and terrorist financing, prevention of criminal acts that may endanger our assets, and compliance with sanctions requirements, we are obliged to take precautions which also include data analyses of your identification data, transaction data, and tax data, for example in relation to your transactions. These measures also serve to protect you.
8. Data Recipients
Your data will only be disclosed in compliance with banking secrecy and only insofar as a legal basis permits this (in particular for the execution of your orders).
Within our bank, those departments receive your data which require them to fulfil our contractual and legal obligations or to perform their respective tasks (for example, credit department, customer service, anti-money laundering officer).
In addition, the following entities may receive your data where and insofar as a legal basis exists:
- processors used by us (Art. 28 GDPR), in particular in the area of IT services, which process your data on our instructions
- public authorities and institutions (for example, Deutsche Bundesbank, Federal Financial Supervisory Authority, European Banking Authority, European Central Bank, tax authorities) where a legal or regulatory obligation or another legal basis exists
- other credit/financial institutions, correspondent banks, clearing/settlement institutions (for example, within SEPA, TARGET, SWIFT)
- our Parent Company, which provides certain IT systems to us as a processor, for example
- external lawyers, data protection officers, courts, arbitration and mediation bodies, auditors and auditors-in-charge
- credit agencies and business information services (for example, within the scope of permissible inquiries by us)
- consulting firms and outsourcing service providers, as well as
- other entities to which you have given us your consent to transfer data.
9. Retention Period
Where necessary, we process your personal data for the duration of our business relationship, which also includes the initiation and execution of a contract between us and the customer. It should be noted that our business relationship with the customer is often a continuing obligation (credit agreements, account management) that is intended to last for years.
Your data will be regularly deleted once they are no longer required for the fulfilment of contractual or legal obligations or you have withdrawn your consent to processing, unless further processing is necessary for the following reasons: Retention and documentation obligations a rising, among other things, from the Commercial Code (HGB), the Fiscal Code (AO), the Banking Act (KWG), or the Anti-Money Laundering Act (GWG). The periods prescribed therein for retention or documentation are two to ten years.
According to the statutory limitation periods, which under §§ 195 et seq. of the Civil Code (BGB) generally amount to three years but may in certain cases be up to thirty years.
10. Transfer to Third Countries
We transfer your data to countries outside the European Economic Area (EEA) (so-called “third countries”) only insofar as this is necessary for the performance of our contract with the customer or the execution of your orders (for example, transfers), or required by law, or you have given us your consent, or within the scope of processing by a processor.
Insofar as we transfer data to our Parent Company in Korea, the following applies: The European Commission determined by Decision (EU) 2022/254 of 17 December 2021 that the Republic of Korea (South Korea) ensures an adequate level of protection for personal data in accordance with the GDPR.
If we transfer data to companies in the USA that are certified under the EU–US Data Privacy Framework, this ensures an adequate level of protection.
In all other cases, unless otherwise stated, we have concluded a contract with the data recipients in the third country based on the EU Standard Contractual Clauses to ensure an adequate level of protection. You may request a copy of the EU Standard Contractual Clauses used from us.
11. Rights of the Data Subject
Under the respective legal conditions, you have the following rights concerning your personal data:
- right of access (Art. 15 GDPR, § 34 BDSG),
- right to rectification (Art. 16 GDPR),
- right to erasure (Art. 17 GDPR, § 35 BDSG),
- right to restriction of processing (Art. 18 GDPR),
- right to data portability (Art. 20 GDPR),
- right to withdraw consent (Art. 7 para. 3 GDPR),
- right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR in conjunction with § 19 BDSG), and
- the following rights to object (Art. 21 GDPR):
Right to object due to a particular situation in case of balancing of interests
You have the right, on grounds relating to your particular situation, to object at any time to the processing of personal data concerning you which is based on Art. 6 para. 1 lit. f GDPR (data processing on the basis of a balancing of interests). This also applies to profiling based on this provision within the meaning of Art. 4 No. 4 GDPR.
If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights, and freedoms, or the processing serves the establishment, exercise, or defense of legal claims.
Right to object to data processing for direct marketing purposes
We may also process your data for direct marketing purposes within the framework of statutory provisions. You have the right to object at any time to the processing of personal data concerning you for such advertising purposes. This also applies to profiling insofar as it is associated with such direct marketing.If you object to processing for direct marketing purposes, we will no longer process your personal data for these purposes.
The objection may be made in any form. You can find our contact details under section 1.
Data Protection Information for Business Partners of KEB Hana Bank (D) AG
Introduction
With this data protection information, we inform our current and prospective business partners, including suppliers, service providers, vendors, contractors, consultants, office visitors, correspondent banks and other financial institution counterparties, as well as other business contacts that are not our customers (together the “Business Partners”) in accordance with the European General Data Protection Regulation (GDPR), about the processing of their personal data by us as well as about their rights. These notices will be updated as necessary and published at www.kebhana.de/datenschutz.
This data protection information applies to you if you are a Business Partner yourself or act on behalf of a Business Partner, for example as a board member, managing director, partner, authorized representative, employee, beneficial owner or other contact person of the Business Partner (together “Data Subjects”). If other Data Subjects act on your behalf in connection with our business relationship (for example employees, sub-contractors or agents), please pass on this data protection information to them as appropriate.
Which data are processed in detail and how they are used depends on the nature of the respective business relationship (for example: provision of goods or services to us, performance of a correspondent banking or interbank relationship, or other business contact).
Controller and Contact
The data controller within the meaning of the GDPR is
KEB Hana Bank (D) AG Bockenheimer Landstr. 33–35 60325 Frankfurt am Main Germany Telephone: +49 69 7129-0 This email address is being protected from spambots. You need JavaScript enabled to view it.
The contact details of our Data Protection Officer are:
This email address is being protected from spambots. You need JavaScript enabled to view it.
This data protection information also applies to our legally dependent branches, for example our branch in Poland. These are part of the entity mentioned above and are not independent controllers within the meaning of the GDPR.
Categories of Data
We process data that we receive in connection with the business relationship with you or the Business Partner you represent. We collect such data directly from you, from the Business Partner, from other companies, or from third parties (in each case in compliance with data protection law).
Specifically, we process in particular the following categories of data:
- Contact and master data: name, business address, business telephone and e-mail address, job title, department or function, language, role within the Business Partner.
- Identification data: data processed for the purpose of identifying you or the Business Partner, for example personal details collected for KYC purposes, identity card or passport data, date and place of birth, nationality, residential address, tax identification numbers, national identification numbers, information on beneficial owners, signature cards and powers of attorney, status as a politically exposed person (PEP).
- Contract and order data: contractual documentation, orders placed, deliveries received, services provided, performance data, complaints, dispute and warranty information.
- Payment and banking data: bank account details, IBAN/BIC, correspondent and clearing account information, payment instructions, SWIFT/SEPA/TARGET data, credit/debit card information, tax data required for payment processing, and other data required for invoicing, accounting, settlement and the prevention of fraud.
- Credit and compliance data: credit rating documentation, financial information of the Business Partner, sanctions and embargo screening results, information on material criminal, regulatory, sanctions-related or insolvency proceedings involving Data Subjects, in each case to the extent relevant e.g. for Know-Your-Customer, Anti-Money-Laundering, sanctions, credit or reputational risk assessment, anti-bribery and counter-terrorist-financing information.
- Correspondence data: data from correspondence with you, including written communication, e-mails, calls (where logged), records of meetings and visitor data.
- Marketing and sales data: data relating to products or services that may be of mutual interest, including information on relationship-management activities towards business contacts.
- Technical data: log files, access logs, IP addresses, device identifiers, session data and other IT-security-related information, in particular where you access our systems, portals or buildings.
- Visitor data: data collected when you visit our premises, for example for access control, reception logs and the use of our guest Wi-Fi (e.g. first name, last name and business e-mail address provided in the course of voucher-based Wi-Fi access).
- Other personal data that is necessary for us to perform compliance duties or satisfy legal requirements (for example as part of the KYC process, sanctions and watchlist screening or PEP screening) and that is processed in compliance with data protection provisions.
Obligation to Provide Data
Within our business relationship with the Business Partner, you are only required to provide those personal data that are necessary for the establishment, performance and termination of the business relationship, or which we are legally obliged to collect.
Without these data, we will generally be unable to enter into or to continue the business relationship with the Business Partner, to perform our contractual obligations or to execute orders. In particular, under the provisions of anti-money-laundering law and supervisory law (in particular the German Banking Act (KWG) and the German Anti-Money Laundering Act (GwG)), we are obliged to identify the Business Partner and, where applicable, its representatives and beneficial owners prior to establishing a business relationship, for example on the basis of identity documents, and to collect their name, place and date of birth, nationality and address. To enable us to comply with these legal obligations, you must provide us with the necessary information and documents and promptly notify us of any changes arising during the course of the business relationship. If the required information and documents are not provided, we may not be able to establish or continue the business relationship.
In all other cases, the provision of personal data may be on a voluntary basis.
Sources of Data
We receive the data directly from you, from the Business Partner you represent, or, where permissible, from third parties, for example from the Business Partner’s contractual partners, payment service providers or correspondent banks.
In addition, we may, where permissible, obtain data from public sources (for example commercial and association registers, land registers, press and other media, the internet), from credit agencies and business information services, from sanctions and PEP databases, from public authorities (for example residents’ registration offices) and from our parent company,
Hana Bank Co., Ltd. (trading as KEB Hana Bank), 35 Eulji-ro, Jung-gu, Seoul 04523, Republic of Korea (“Parent Company”),
as well as from other companies of the Hana Financial Group.
Purpose of Processing and Legal Basis
We process personal data in accordance with the provisions of the GDPR and applicable national data protection law. Below, we inform you about the purposes for which and the legal bases on which we process your data.
For the Initiation, Performance and Termination of Contracts (Art. 6 para. 1 lit. b GDPR)
We process the Data Subjects’ personal data to initiate, perform and terminate our contracts with Business Partners, for example to communicate about products and services, to respond to inquiries, to enter into contracts, to fulfil orders, to receive and verify deliveries and services, to verify a Data Subject’s identity, to process payments, for accounting, verification, billing or collection purposes, and to manage the on-going relationship with the Business Partner.
To the extent that the contractual partner is not the Data Subject personally but the Business Partner on whose behalf the Data Subject acts (which is the regular case for representatives, employees and beneficial owners of a corporate Business Partner), the legal basis for the processing is Art. 6 para. 1 lit. f GDPR (balancing of interests, see below).
Within the Scope of the Balancing of Interests (Art. 6 para. 1 lit. f GDPR)
We also process your data beyond the actual performance of the contract on the basis of a balancing of interests to safeguard our legitimate interests or those of third parties. This takes place, each within the limits of what is legally permissible, for the following purposes:
- general business management and further development of services and products
- managing relationships with Business Partners, including communication with their representatives, employees and beneficial owners
- procurement, vendor management and supplier risk management
- correspondent banking and interbank relationship management, including SWIFT/SEPA/TARGET processing
- internal reporting, group reporting and consolidated reporting within the Hana Financial Group
- advertising, market and opinion research, including business-relationship-management activities
- assertion of legal claims and defence in legal disputes and securing of relevant evidence
- prevention and investigation of criminal offences
- ensuring IT security, physical security of our premises, and IT operations
- ensuring effective and efficient compliance with statutory and regulatory provisions, and demonstrating such compliance
- identification, assessment and control of risks (including counterparty, credit, operational, compliance and reputational risks)
- prevention, detection and termination of fraud and abuse
- preparation and execution of corporate transactions (e.g. M&A, outsourcing arrangements)
- preparation of analyses, reports and evaluations for the development and improvement of our products, services and internal processes and for business management.
The interests in the respective processing arise from the aforementioned purposes and also include:
- improvement of our internal processes as well as our services and products
- increase of efficiency and profitability (for example through centralization and standardization of processes and functions within the KEB Hana Group, including the use of group-wide IT systems and specialized service providers)
- protection of assets (for example against fraud), property and health
- ensuring information security and data protection.
To the extent possible and reasonable based on the specific purpose, we process your data in an anonymized or pseudonymized manner.
Based on Your Consent (Art. 6 para. 1 lit. a GDPR)
Where you have given us consent to process personal data, this consent constitutes the legal basis for the processing referred to therein. This applies in particular to your possible consent to receive marketing communications. You may withdraw your consent at any time with effect for the future. This also applies to declarations of consent given to us prior to the GDPR. The withdrawal applies only to future processing of data.
Based on Legal Obligations (Art. 6 para. 1 lit. c GDPR)
We are subject to various legal obligations, that is statutory requirements (for example the German Banking Act (KWG), the German Anti-Money Laundering Act (GwG), tax laws, foreign trade law, sanctions regimes, payment system regulations and commercial law) as well as supervisory requirements (for example of the European Central Bank, the European Banking Authority, the Deutsche Bundesbank and the Federal Financial Supervisory Authority, BaFin). The purposes of processing include identity verification, fraud, money-laundering and terrorist-financing prevention, compliance with tax control and reporting obligations, accounting and book-keeping retention obligations, and the assessment and management of risks.
Sanctions and Watchlist Screening
In order to comply with statutory and regulatory obligations under foreign trade law, EU and international sanctions regimes (in particular EU regulations on restrictive measures), as well as anti-money-laundering and counter-terrorist-financing rules, we screen Business Partners as well as Data Subjects acting on their behalf, including representatives, contact persons, beneficial owners and parties to payment transactions, against applicable sanctions lists, watchlists and PEP (politically exposed persons) lists. This screening is carried out both at the establishment of the business relationship and on an on-going basis during its term, and may also be performed in connection with individual payment transactions. The legal basis is Art. 6 para. 1 lit. c GDPR (compliance with legal obligations) and, where applicable, Art. 6 para. 1 lit. f GDPR (legitimate interests in preventing financial crime and reputational harm).
Nature of Processing, Profiling
Within the scope of the aforementioned processing operations, we may, in compliance with legal requirements, also use data for the development, training, application, improvement and monitoring of artificial intelligence models and systems. Possible areas of application include, for example, the recording and classification of data (for example in incoming documents and invoices), the recognition of patterns and relationships in large data sets (for example for combating fraud, sanctions screening, or in procurement and supplier management), and support for process automation.
We may process your data partly automatically with the aim of evaluating certain personal aspects (so-called “profiling” according to Art. 4 No. 4 GDPR). We may use profiling, for example, in the following cases: Based on statutory, regulatory and sanctions-related requirements in the context of combating money laundering and terrorist financing, prevention of criminal acts that may endanger our assets, and compliance with sanctions requirements, we are obliged to take precautions which also include data analyses of identification data, transaction data and tax data, for example in relation to payments to or from the Business Partner. These measures also serve to protect you.
Data Recipients
Your data will only be disclosed where permitted by applicable law and in compliance with applicable banking secrecy obligations.
Within our bank, those departments receive your data which require them to fulfil our contractual and legal obligations or to perform their respective tasks (for example procurement, accounting, payment operations, credit department, customer service, anti-money-laundering officer, compliance, IT security).
In addition, the following entities may receive your data where and insofar as a legal basis exists:
- Processors used by us (Art. 28 GDPR), in particular in the area of IT services, printing and logistics, document processing, archiving and destruction, and other support functions, which process your data on our instructions
- Public authorities and institutions (for example Deutsche Bundesbank, Federal Financial Supervisory Authority, BaFin, European Banking Authority, European Central Bank, tax authorities, customs authorities, law enforcement authorities) where a legal or regulatory obligation or another legal basis exists
- Other credit/financial institutions, correspondent banks, clearing and settlement institutions (for example within SEPA, TARGET, SWIFT), to the extent necessary for processing payments and other transactions
- Our Parent Company and other entities of the Hana Financial Group, in particular where they provide IT systems or other support functions to us as processors (for example for IT services, credit assessment, KYC support, refinancing), or for group reporting and consolidated supervision purposes
- External lawyers, data protection officers, courts, arbitration and mediation bodies, auditors and auditors-in-charge
- Credit agencies and business information services (for example within the scope of permissible inquiries by us)
- Consulting firms, outsourcing service providers and other advisors, as well as
- Other recipients to which you have given us your consent to transfer data, or to which a transfer is required to investigate or prevent illegal activities, fraud or potential threats to the safety of any person.
Retention Period
We process your personal data only as long as necessary for the purpose for which the data were collected, or as long as we are permitted or required to do so under applicable law.
As a rule, we process your personal data for the duration of our business relationship, which also includes the initiation and processing of a contract. Longer retention periods may result from various statutory retention and documentation obligations, among other things from the Commercial Code (HGB), the Fiscal Code (AO), the Banking Act (KWG) or the Anti-Money Laundering Act (GwG). The periods prescribed therein for retention or documentation are typically two to ten years.
In addition, we may store your data for a reasonable period in order to be able to prove compliance with legal obligations and to defend ourselves against claims. According to the statutory limitation periods under §§ 195 et seq. of the German Civil Code (BGB), claims generally become time-barred after three years; in certain cases the limitation period may be up to thirty years.
Transfer to Third Countries
We transfer your data to countries outside the European Economic Area (EEA) (“third countries”) only insofar as this is necessary for the performance of our contract with the Business Partner or the execution of an order, or required by law, or you have given us your consent, or within the scope of processing by a processor.
Insofar as we transfer data to our Parent Company in Korea, for example in the context of IT services, credit assessment, KYC support or refinancing provided to us by the Parent Company, the following applies: The European Commission determined by Decision (EU) 2022/254 of 17 December 2021 that the Republic of Korea (South Korea) ensures an adequate level of protection for personal data in accordance with the GDPR.
If we transfer data to companies in the USA that are certified under the EU–US Data Privacy Framework, this ensures an adequate level of protection.
In all other cases, unless otherwise stated, we have concluded a contract with the data recipients in the third country based on the EU Standard Contractual Clauses to ensure an adequate level of protection. You may request a copy of the EU Standard Contractual Clauses used from us.
Rights of the Data Subject
Under the respective legal conditions, you have the following rights concerning your personal data:
- right of access (Art. 15 GDPR, § 34 BDSG)
- right to rectification (Art. 16 GDPR)
- right to erasure (Art. 17 GDPR, § 35 BDSG)
- right to restriction of processing (Art. 18 GDPR)
- right to data portability (Art. 20 GDPR)
- right to withdraw consent (Art. 7 para. 3 GDPR)
- right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR in conjunction with § 19 BDSG), and
- the following rights to object (Art. 21 GDPR):
Right to object due to a particular situation in case of balancing of interests You have the right, on grounds relating to your particular situation, to object at any time to the processing of personal data concerning you which is based on Art. 6 para. 1 lit. f GDPR (data processing on the basis of a balancing of interests). This also applies to profiling based on this provision within the meaning of Art. 4 No. 4 GDPR. If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defense of legal claims. |
Right to object to data processing for direct marketing purposes
We may also process your data for direct marketing purposes within the framework of statutory provisions. You have the right to object at any time to the processing of personal data concerning you for such marketing purposes. This also applies to profiling insofar as it is associated with such direct marketing.
If you object to processing for direct marketing purposes, we will no longer process your personal data for these purposes. The objection may be made in any form. You can find our contact details under the section “Controller and Contact”.



