Information on data protection

In this privacy notice, we set out how we handle your personal data and explain your rights under the European General Data Protection Regulation (GDPR) and the Federal Data Protection Act (BDSG). The data controller is the KAIFU-NORDLAND eG housing cooperative (hereinafter referred to as “we” or “us”). 

 

Contents

I. General information
1. Contact
2. Legal basis
3. Retention
period 4. Categories of data
recipients 5. Data transfers to third countries
6. Processing in connection with the exercise of your rights
7. Your rights
8.  Right
to object 9. Data Protection Officer
II. Data processing on our website
1. Processing of server log files
2. Reporting
repair requirements 3.  Member
login 4. Job applications
5. Cookies
6. My Fonts
III. Data processing on our social media pages
1. Visiting a social media page
a) LinkedIn company page
b) Xing
2.  Comments and direct messages
IV. Other data processing
activities 1. Job applications
2. Contact via email
3. Customer and prospect data

I. General Information

1. Contact
If you have any questions or suggestions regarding this information, or if you wish to contact us to exercise your rights, please address your enquiry to 

KAIFU-NORDLAND eG
Housing Cooperative Kieler Straße 131
22769 Hamburg
Germany
Telephone: 040 4317 02 0
Email: info@kaifu.de

2. Legal
Basis The data protection term ‘personal data’ refers to all information relating to an identified or identifiable natural person. We process personal data in compliance with the relevant data protection regulations, in particular the GDPR and the BDSG. We only process data on the basis of a legal authorisation. We process personal data only with your consent (Section 25(1) TDDDG or Article 6(1)(a) of the GDPR), to fulfil a contract to which you are a party or, at your request, to take steps prior to entering into a contract (Article 6(1)(b) of the GDPR), to comply with a legal obligation (Article 6(1)(c) of the GDPR) or where processing is necessary to safeguard our legitimate interests or the legitimate interests of a third party, provided that your interests or fundamental rights and freedoms requiring the protection of personal data do not take precedence (Article 6(1)(f) of the GDPR). 

If you apply for a vacancy within our company, we also process your personal data for the purpose of deciding whether to enter into an employment relationship (Section 26(1), first sentence, of the German Federal Data Protection Act (BDSG)).

3. Duration of storage
Unless otherwise stated in the following information, we store the data only for as long as is necessary to fulfil the purpose of processing or to meet our contractual or statutory obligations. Such statutory retention obligations may arise, in particular, from commercial or tax law provisions. From the end of the calendar year in which the data was collected, we will retain personal data contained in our accounting records for ten years and personal data contained in commercial correspondence and contracts for six years. Furthermore, we will retain data relating to consents for which proof is required, as well as to complaints and claims, for the duration of the statutory limitation periods. We will delete data stored for marketing purposes if you object to its processing for this purpose.

4. Categories of data
recipients We engage data processors in connection with the processing of your data. The processing operations carried out by such data processors include, for example, hosting, email dispatch, maintenance and support of IT systems, contract management, bookkeeping and invoicing, marketing activities, or the destruction of files and data storage media. A data processor is a natural or legal person, public authority, agency or other body that processes personal data on behalf of the data controller. Data processors do not use the data for their own purposes, but carry out data processing exclusively on behalf of the data controller and are contractually obliged to ensure appropriate technical and organisational measures for data protection. In addition, we may transfer your personal data to bodies such as postal and courier services, our principal bank, tax consultancy or auditing firms, or the tax authorities. Further recipients may be identified in the following information. 

5. Data transfers to third countries
Our data processing activities may involve the transfer of certain personal data to third countries, i.e. countries where the GDPR is not applicable. Such a transfer is permitted if the European Commission has determined that an adequate level of data protection is ensured in that third country. If no such adequacy decision has been issued by the European Commission, the transfer of personal data to a third country will only take place if suitable safeguards are in place in accordance with Article 46 of the GDPR or if one of the conditions set out in Article 49 of the GDPR is met.

Unless otherwise stated below, we use the EU Standard Data Protection Clauses as suitable safeguards for the transfer of personal data to third countries. You have the option to receive a copy of these EU Standard Data Protection Clauses or to view them. To do so, please contact us at the address provided under ‘Contact’.  

If you consent to the transfer of personal data to third countries, the transfer takes place on the legal basis of Article 49(1)(a) of the GDPR. 

6. Processing in connection with the exercise of your rights 
When you exercise your rights under Articles 15 to 22 of the GDPR, we process the personal data provided for the purpose of implementing these rights and to be able to provide evidence thereof. We will process data stored for the purpose of providing information and preparing such information solely for this purpose and for the purposes of data protection monitoring; in all other respects, we will restrict processing in accordance with Article 18 of the GDPR. 

This processing is based on the legal basis of Article 6(1)(c) of the GDPR in conjunction with Articles 15 to 22 of the GDPR and Section 34(2) of the BDSG.

7. Your rights
As a data subject, you have the right to exercise your data subject rights vis-à-vis us. In particular, you have the following rights:
•  In accordance with Article 15 of the GDPR and Section 34 of the BDSG, you have the right to request information as to whether, and if so to what extent, we process personal data relating to you. 
• You have the right, in accordance with Article 16 of the GDPR, to request that we rectify your data.
• You have the right, in accordance with Article 17 of the GDPR and Section 35 of the BDSG, to request that we erase your personal data.
•  You have the right, in accordance with Article 18 of the GDPR, to have the processing of your personal data restricted.
•  You have the right, in accordance with Article 20 of the GDPR, to receive the personal data concerning you that you have provided to us in a structured, commonly used and machine-readable format, and to transmit this data to another controller.
•  If you have given us separate consent to the processing of your data, you may withdraw this consent at any time in accordance with Article 7(3) of the GDPR. Such a withdrawal does not affect the lawfulness of processing carried out on the basis of consent prior to the withdrawal.
• If you consider that the processing of your personal data infringes the provisions of the GDPR, you have the right to lodge a complaint with a supervisory authority in accordance with Article 77 of the GDPR.

8. Right
to object In accordance with Article 21(1) of the GDPR, you have the right to object to processing based on Article 6(1)(e) or (f) of the GDPR on grounds relating to your particular situation. Where we process your personal data for the purposes of direct marketing, you may object to such processing in accordance with Article 21(2) and (3) of the GDPR.

9. Data Protection Officer
You can contact our Data Protection Officer using the following details:

Email: datenschutzbeauftragter@kaifu.de 
Herting Oberbeck Datenschutz GmbH
Hallerstr. 76, 20146 Hamburg
https://www.datenschutzkanzlei.de    

II. Data processing on our website

When you use the website, we collect information that you provide yourself. In addition, during your visit to the website, we automatically collect certain information about your use of the website. Under data protection law, an IP address is generally also considered to be personal data. An IP address is assigned to every device connected to the internet by the internet service provider so that it can send and receive data.

1. Processing of server log files
When you use our website for purely informational purposes, general information transmitted by your browser to our server is initially stored automatically (i.e. not via registration). By default, this includes: browser type and version, operating system used, page accessed, the previously visited page (referrer URL), IP address, date and time of the server request, and HTTP status code. 

This processing is carried out to safeguard our legitimate interests and is based on the legal basis of Article 6(1)(f) of the GDPR. This processing serves the purposes of technical administration and website security. The stored data is deleted after seven days, unless there are specific grounds for a legitimate suspicion of unlawful use and further examination and processing of the information is required for this reason. We are unable to identify you as a data subject on the basis of the stored information. Articles 15 to 22 of the GDPR therefore do not apply in accordance with Article 11(2) of the GDPR, unless you provide additional information enabling your identification in order to exercise your rights set out in these articles.

2. Reporting
the need for repairs Our website contains a contact form for reporting the need for repairs, which you can use to inform us of any damage to one of our properties. Your data is transferred in encrypted form (as indicated by ‘https’ in the browser’s address bar). All data fields are required to process your enquiry. Failure to provide this information means that we will be unable to process your enquiry. Alternatively, you can send us a message via the contact email address. We process the data for the purpose of responding to your enquiry and, where necessary, pass it on to service providers or tradespeople for the purpose of carrying out repairs. We process the data on the basis of our legitimate interest in contacting those who submit enquiries. The legal basis for data processing is Article 6(1)(f) of the GDPR.

3. Member
login Our website contains a secure area where our members can find out about available rental properties and apply to become tenants. Access to the restricted area is granted by entering a membership number and a password. The data is transferred in encrypted form (as indicated by ‘https’ in the browser’s address bar). We process the data on the basis of the contractual relationship with our members, which obliges us to give them priority access to property listings. The legal basis for data processing is Article 6(1)(b) of the GDPR.

4. Job applications
You have the option to apply for a position with us via the ‘Job Vacancies’ section. To do so, you will be redirected to the website of our service provider, softgarden e-recruiting GmbH (Germany/EU). Further information on the processing of your data when submitting an application can be found at the following link: https://kaifu.de/sites/default/files/2024-08/datenverarbeitung_kaifu_02… .

5. Cookies
We use cookies and similar technologies (‘cookies’) on our website. Cookies are small data files stored by your browser when you visit a website. This identifies the browser being used and allows it to be recognised by web servers. You have full control over the use of cookies via your browser. You can delete cookies at any time in your browser’s security settings. You can object to the use of cookies via your browser settings, either in general or in specific cases. 

The use of cookies is technically necessary for the operation of our website and is therefore permitted without the user’s consent. 

6. My Fonts
We use web fonts from Monotype Imaging Holdings Inc., USA (‘Monotype’) on our website to ensure consistent font display. When you visit a page, your browser downloads the required web fonts from our web server into your browser cache in order to display text and fonts correctly. For licensing reasons, it is necessary to count page views; for this reason, your browser establishes a connection to fonts.com or fast.fonts.net and transmits the website operator’s customer ID. This data processing is carried out to safeguard our legitimate interests in ensuring a consistent and appealing presentation of our website and is based on the legal basis of Article 6(1)(f) of the GDPR.

No cookies are set in the process. You may object to this data processing at any time via the settings of your browser or certain browser extensions. One such extension is, for example, the matrix-based firewall uMatrix for the Firefox and Google Chrome browsers. Please note that this may result in functional limitations on the website. If your browser does not support web fonts, a standard font from your computer will be used.

Further information on this processing activity, the technologies used, the data stored and the retention period can be found in Monotype’s privacy policy at www.monotype.com/de/rechtshinweise/datenschutzrichtlinie/datens

Please also refer to the information in the section ‘Data transfers to third countries’.

III. Data processing on our social media pages

We maintain company pages on several social media platforms. Through these, we aim to provide further opportunities to learn about our company and to engage in dialogue. Our company has pages on the following social media platforms:


LinkedIn – Xing

If you visit or interact with a profile on a social media platform, personal data relating to you may be processed. The information associated with a social media profile you use also regularly constitutes personal data. This includes messages and statements made whilst using the profile. Furthermore, when you visit a social media profile, certain information about it is often collected automatically, which may also constitute personal data.

1. Visiting a social media page
a) LinkedIn company page
LinkedIn Ireland Unlimited Company (Ireland/EU – ‘LinkedIn’) is generally the sole data controller responsible for the processing of personal data when you visit our LinkedIn page. Further information on the processing of personal data by LinkedIn is available at https://www.linkedin.com/legal/privacy-policy?trk=homepage-basic_footer….

When you visit our LinkedIn company page, follow this page or engage with it, LinkedIn processes personal data in order to provide us with statistics and insights in anonymised form. This enables us to gain an understanding of the types of actions that people take on our page (so-called ‘Page Insights’). To this end, LinkedIn processes, in particular, data that you have already provided to LinkedIn via the information in your profile, such as data on your job title, country, sector, length of service, company size and employment status. In addition, LinkedIn will process information about how you interact with our LinkedIn company page, e.g. whether you are a follower of our LinkedIn company page. LinkedIn does not provide us with any of your personal data via Page Insights. We only have access to the aggregated Page Insights. Nor is it possible for us to draw conclusions about individual members from the information in the Page Insights. This processing of personal data within the scope of Page Insights is carried out by LinkedIn and us as joint controllers. The processing serves our legitimate interest in analysing the types of actions taken on our LinkedIn company page and improving our company page based on these insights. The legal basis for this processing is Article 6(1)(f) of the GDPR. We have entered into an agreement with LinkedIn regarding processing as joint controllers, which sets out the allocation of data protection obligations between us and LinkedIn. The agreement is available at: https://legal.linkedin.com/pages-joint-controller-addendum. Accordingly, the following applies:

• LinkedIn and we have agreed that LinkedIn is responsible for enabling you to exercise your rights under the GDPR. You can contact LinkedIn online via the following link (https://www.linkedin.com/help/linkedin/ask/PPQ?lang=de) or reach out to LinkedIn using the contact details provided in its privacy policy. You can contact the Data Protection Officer at LinkedIn Ireland via the following link: https://www.linkedin.com/help/linkedin/ask/TSO-DPO. You may also contact us using the contact details provided to exercise your rights in relation to the processing of personal data in the context of Page Insights. In such cases, we will forward your enquiry to LinkedIn.

• LinkedIn and we have agreed that the Irish Data Protection Commission is the lead supervisory authority responsible for overseeing the processing of Page Insights. You always have the right to lodge a complaint with the Irish Data Protection Commission (see www.dataprotection.ie) or with any other supervisory authority.

Please note that, in accordance with LinkedIn’s Privacy Policy, personal data is also processed by LinkedIn in the USA or other third countries. In doing so, LinkedIn only transfers personal data to countries for which the European Commission has issued an adequacy decision pursuant to Article 45 of the GDPR or on the basis of appropriate safeguards pursuant to Article 46 of the GDPR. 

b) Xing
New Work SE (Germany/EU) is generally the sole data controller responsible for the processing of personal data when you visit our Xing profile. Further information on the processing of personal data by New Work SE is available at https://privacy.xing.com/de/datenschutzerklaerung

2. Comments and direct messages
We also process information that you have provided to us via our company page on the relevant social media platform. Such information may include the username used, contact details or a message sent to us. We carry out this processing as the sole data controller. We process this data on the basis of our legitimate interest in contacting enquirers. The legal basis for the data processing is Article 6(1)(f) of the GDPR. Further data processing may take place if you have given your consent (Article 6(1)(a) of the GDPR) or if this is necessary to comply with a legal obligation (Article 6(1)(c) of the GDPR).

IV. Further data processing

1. Job Applications
If you apply for a job with our company, we process your application data exclusively for purposes relating to your interest in current or future employment with us and the processing of your application. Your application will only be processed and reviewed by the relevant contact persons within our organisation. All employees entrusted with data processing are obliged to maintain the confidentiality of your data. Should we be unable to offer you employment, we will retain the data you have provided for up to six months following any rejection, for the purpose of answering questions relating to your application and the rejection. This does not apply where statutory provisions preclude deletion, where further storage is necessary for the purposes of providing evidence, or where you have expressly consented to longer-term storage. The legal basis for data processing is Section 26(1), first sentence, of the Federal Data Protection Act (BDSG). Should we retain your application data for longer than six months and you have given your express consent to this, we would like to point out that this consent may be freely withdrawn at any time in accordance with Article 7(3) of the GDPR. Such a withdrawal does not affect the lawfulness of the processing carried out on the basis of your consent up until the time of withdrawal.

2. Contact via email
If you send us a message via the contact email address provided, we will process the data transmitted for the purpose of responding to your enquiry. We process this data on the basis of our legitimate interest in contacting enquirers. 

The legal basis for data processing is Article 6(1)(f) of the GDPR.

3. Customer and prospective customer data
When you contact our company as a customer or prospective customer, we process your data to the extent necessary to establish or fulfil the contractual relationship. This regularly includes the processing of the personal master data, contractual data and payment data provided to us, as well as the contact and communication details of our points of contact at commercial customers and business partners. The legal basis for this processing is Article 6(1)(b) of the GDPR for end customers and Article 6(1)(f) of the GDPR when we contact representatives of business customers. 

We also process customer and prospect data for analysis and marketing purposes. This processing is carried out on the legal basis of Article 6(1)(f) of the GDPR and serves our interest in further developing our range of services and providing you with targeted information about our offers. 

Further data processing may take place if you have given your consent (Article 6(1)(a) of the GDPR) or if this is necessary to comply with a legal obligation (Article 6(1)(c) of the GDPR).