The following data protection statement, i.e. privacy policy, is intended to inform you about which types of personal data (hereinafter also referred to as "data") we process, for what purposes and to what extent. This data protection statement applies to all processing of personal data carried out by us, both in the context of providing our services and, in particular, on our websites, in mobile applications and within external online services, such as our social media profiles (hereinafter collectively referred to as "online services").
The terms used are not gender-specific.
As of 13 February 2020
RCS Entsorgung GmbH
Capeller Straße 147
59368 Werne
Deutschland
RCS Rohstoffverwertung GmbH
Capeller Straße 147
59368 Werne
Deutschland
Capeller Straße 147
59368 Werne
Deutschland
E-mail address: datenschutz(at)rcs-entsorgung.de
Phone: 02389/9826-0
Legal Notice: rcs-entsorgung.de/de/legal-notice
RCS Entsorgung GmbH
Marco Exner
Capeller Straße 147
59368 Werne
Deutschland
RCS Rohstoffverwertung GmbH
Marco Exner
Capeller Straße 147
59368 Werne
Deutschland
Capeller Straße 147
59368 Werne
Deutschland
E-mail address: datenschutz(at)rcs-entsorgung.de
The following overview summarises the types of data processed and the purpose of such processing, in addition to providing details of the data subjects.
Types of data processed
Categories of data subjects
Purpose of processing
The following section outlines the legal fundamentals of the General Data Protection Regulation (GDPR) that form the basis for the processing of personal data. Please note that in addition to the regulations of the GDPR, national data protection regulations may apply in your or our country of residence and domicile. If, in addition, other specific legal bases are applicable in individual cases, we will inform you of these in the data protection statement.
National data protection regulations in Germany: In addition to the data protection provisions set out in the General Data Protection Regulation, specific national regulations on data protection apply in Germany. They include in particular the Federal Act on Protection Against Misuse of Personal Data in Data Processing (Federal Data Protection Act (Bundesdatenschutzgesetz – BDSG)). In particular, the BDSG contains special regulations on the right of access to information, the right of erasure/deletion, the right of objection, the processing of special categories of personal data, processing for other purposes and transmission as well as automated decision-making in individual cases, including profiling. Furthermore, it regulates data processing for purposes of the employment relationship (Section 26 BDSG), in particular with regard to the conclusion, implementation or termination of employment and the consent of employees. Furthermore, state data protection laws of the individual federal states may apply.
We take appropriate technical and organisational measures in accordance with legal requirements, taking into account the state of the art, implementation costs and the nature, scope, circumstances and purposes of processing as well as the varying degrees of probability of occurrence and the extent of the threat to the rights and freedoms of natural persons, in order to ensure a level of protection commensurate with the risk.
These measures shall include, in particular, ensuring the confidentiality, integrity and availability of data by controlling physical and electronic access to the data as well as access, input, disclosure, safeguarding of availability and segregation thereof. In addition, we have established procedures to ensure that the rights of data subjects are exercised, that data is deleted and that we are able to respond to any threats to the data. Furthermore, we take the protection of personal data into account as early as the stage of development or selection of hardware, software and processes in accordance with the principle of data protection, through technology design and through data protection-friendly presettings.
Truncation of IP address: If it is possible or not necessary for us to save your IP address, we will shorten or have your IP address shortened (truncation). In the case of IP address truncation, also known as IP masking, the last octet, i.e. the last two numbers of an IP address, is deleted (the IP address in this context is an identifier individually assigned to an Internet connection by the online access provider). The purpose of shortening the IP address is to prevent or make it considerably more difficult to identify a person on the basis of their IP address.
SSL encryption (https): We use SSL encryption to protect your data transmitted via our online service. You can recognise encrypted connections such as these by the prefix https:// in the address line of your browser.
In the course of our processing of personal data, data may be transferred or disclosed to other bodies, companies, legally independent organisational units or persons. The recipients of this data may include, for example, financial institutions in the context of payment transactions, service providers commissioned with the performance of IT-related tasks or providers of services and content integrated into a website. In such cases we observe the legal requirements and in particular conclude appropriate contracts or agreements with the recipients of your data that serve to protect your data.
Data transfer within the organisation: We may transfer or grant access to personal information to other entities within our organisation. If this transfer is for administrative purposes, the transfer of the data is based on our justified entrepreneurial and business interests or is necessary to fulfil our contractual obligations. It may also occur in those cases in which the consent of the person concerned has been given or a legal authorisation exists.
If we process data in a third country (i.e. outside the European Union (EU), the European Economic Area (EEA)) or if the processing takes place in the context of the use of third-party services or the disclosure or transfer of data to other persons, bodies or companies, this is only conducted in accordance with the legal requirements.
Subject to express consent or transfer required by contract or by law, we process or allow the data to be processed only in third countries with a recognised level of data protection, including the US processors certified under the privacy shield, or on the basis of special guarantees, such as contractual obligations through so-called standard protection clauses of the EU Commission, the existence of certifications or binding internal data protection regulations (Art. 44 to 49 GDPR, information page of the EU Commission: https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection_de ).
Cookies are text files that contain data from websites or domains visited by the user; they are stored by a browser on the user's computer. A cookie is primarily used to store information about a user during or after his visit relating to an online service. The stored information may include, for example, the language settings on a website, the login status, a shopping cart or the location where a video was viewed. The term "cookies" also includes other technologies that perform the same functions as cookies (e.g. when user information is stored using pseudonymous online identifiers, also referred to as "user IDs")
We distinguish between the following types of cookie and function:
Information on legal bases: The legal basis on which we process your personal data using cookies depends on whether we ask you for your consent. If this is the case and you consent to the use of cookies, the legal basis for processing your data is the consent given. Otherwise, the data processed with the aid of cookies will be processed on the basis of our legitimate interests (e.g. relating to the business operation of our online service and its improvement) or, if the use of cookies is necessary to fulfil our contractual obligations.
General information on withdrawal of consent and objection (opt-out): Depending on whether the processing is based on consent or legal permission, you may at any time withdraw any consent you have given or object to the processing of your data by cookie technologies (collectively referred to as "opt-out"). You can initially declare your objection using the settings of your browser, e.g. by deactivating the use of cookies (although this may also restrict the functionality of our online service). An objection to the use of cookies for online marketing purposes can also be declared by means of a variety of services, especially in the case of tracking, via the websites https://optout.aboutads.info and https://www.youronlinechoices.com/. In addition, you can receive further notices of objection in the context of the information on the service providers and cookies used.
Processing of cookie data based on consent: Before we process data or have data processed in the context of the use of cookies, we ask users for their consent, which can be revoked at any time. Before consent has not been given, cookies are only used in those cases in which they are deemed necessary for the operation of our online service. Their use is based on our interest and the interest of the users in the expected functionality of our online service.
When contacting us (e.g. via contact form, e-mail, telephone or via social media), the data of the enquiring persons will be processed to the extent necessary to answer the contact enquiries and any requested measures.
Our response to contact enquiries within the scope of contractual or pre-contractual relations is to be seen in the context of the fulfilment of our contractual obligations or for answering (pre-)contractual enquiries and, beyond this, on the basis of the legitimate interest in responding to enquiries.
The data processed as part of the provision of the hosting service may include all information relating to the users of our online service that is generated in the course of use and communication. This regularly includes the IP address, which is necessary to be able to deliver the contents of online services to browsers, and all entries made in the context of our online service or from websites.
Collection of access data and log files: We ourselves (or our web hosting provider) collect data on every access to the server (so-called server log files). Server log files may include the address and name of the web pages and files accessed, date and time of access, data volume transferred, notification of successful access, browser type and version, the user's operating system, referrer URL (the previously visited page) and, as a rule, IP addresses and the requesting provider.
The server log files can be used on the one hand for security purposes, e.g. to avoid overloading the servers (especially in the case of malicious attacks, so-called DDoS attacks), and on the other hand to ensure the utilisation of the servers and their stability.
The application procedure requires applicants to provide us with the data necessary for their assessment and selection. Which information is required can be found in the job description or, in the case of online forms, in the information provided therein.
Fundamentally, the required data includes personal information such as name, address, contact details and proof of the qualifications required for a position. On request, we will also be happy to inform you which information is required.
If provided, applicants can send us their applications using an online form. The data are encrypted and transmitted to us according to the state of the art. Applicants can also send us their applications by e-mail. Please note, however, that e-mails are generally not sent in encrypted form via the Internet. As a rule, e-mails are encrypted in transit, but not on the servers from which they are sent and received. We can therefore not assume any responsibility for the transmission route of the application between the sender and the reception on our server.
For the purposes of applicant search, submitting applications and selecting applicants, we may use applicant management or recruitment software and platforms and services of third parties, subject to the legal requirements.
Applicants are welcome to contact us regarding the method of submitting their application or to send us their application by post.
VProcessing of special categories of data: If special categories of personal data within the meaning of Article 9 paragraph 1 GDPR (e.g. health-related data such as status of severe disability or ethnic origin) are requested from applicants in the context of the application procedure so that the controller or the data subject can exercise the rights associated with labour law and social security and social protection law and fulfil his or her obligations in this respect, processing is carried out in accordance with Art. 9 paragraph 2 point (b) GDPR, in the case of protection of essential interests of applicants or other persons according to Art. 9 paragraph 2 point (c) GDPR or for the purposes of health care or occupational medicine, for the assessment of the employee's working capacity, for medical diagnosis, the provision of health or social care or treatment or the management of health or social care systems and services pursuant to Art. 9 paragraph 2 point (h) GDPR. If the data subject has given explicit consent to the processing of special categories of personal data, the processing of such data is conducted on the basis of Art. 9 paragraph 2 point (a) GDPR.)
Erasure of data: In the event of a successful application, the data provided by the applicants may be further processed by us for the purposes of employment. By contrast, if the application for a job offer is not successful, applicants' data will be erased. Applicants' data is also erased if an application is withdrawn, which applicants are entitled to do at any time. Subject to the justified revocation by applicants, the data will be erased after a period of six months at the latest so that we can answer any follow-up questions about the application and comply with our obligations to provide evidence under the regulations on the equal treatment of applicants. Invoices for any reimbursement of travel expenses will be archived in accordance with tax law requirements.
Admission to a pool of applicants: Admission to a pool of applicants, insofar as this is offered, is based on the provision of consent. Applicants are informed that their consent regarding the inclusion in the talent pool is voluntary, has no influence on the current application procedure, and that they can withdraw their consent at any time in the future.
Web analysis (also known as "reach analysis") is used to evaluate visitor streams associated with our online service and may include visitor information about behaviour, interests or demographics, such as age or gender, as pseudonymous values. With the help of reach analysis, we can, for example, identify at what time our online service or its functions or contents are most frequently used or invite visitors to use them again. This also helps us understand which areas require optimisation.
In addition to web analysis, we can also use test procedures, e.g. to test and optimise different versions of our online service or its components.
For these purposes, so-called user profiles can be created and stored in a file (so-called "cookie") or similar procedures with the same purpose can be used. This information may include, for example, content viewed, web pages visited and elements used on those pages as well as technical details such as the browser used, the computer system used and information on usage times. If users have consented to the collection of their location data, this data may also be processed, depending on the provider.
The IP addresses of users are also stored. However, we use an IP masking procedure (i.e., pseudonymisation by means of IP address truncation) to protect the users. In general, in the context of web analysis, A/B testing and optimization, no clear user data (such as e-mail addresses or names) are stored, only pseudonyms. This means that we as well as the providers of the software used do not know the actual identity of the users, but only the information stored in their profiles for the purposes of the respective procedures.
Notes on legal bases: If we ask users for their consent to use third-party providers, the legal basis for processing data is the provision of consent. Otherwise, users' data will be processed on the basis of our legitimate interests (i.e. interest in efficient, cost-effective and recipient-friendly services). In this context, we would also like to draw your attention to the information on the use of cookies in this privacy policy.
Services and service providers used:
We process personal data for online marketing purposes, which may include, in particular, the marketing of advertising space or the display of advertising and other content (collectively referred to as "content") based on the potential interests of users and the measurement of its effectiveness.
For these purposes, so-called user profiles are created and stored in a file (so-called "cookie") or similar procedures are used, by means of which the user data relevant to the presentation of the aforementioned content are stored. This information may include, for example, the content viewed, web pages visited and online networks used, but also communication partners and technical details such as the browser used, the computer system used and information on usage times. If users have consented to the collection of their location data, this data may also be processed.
The IP addresses of users are also stored. However, we use available IP masking procedures (i.e., pseudonymisation by means of IP address truncation) to protect the users. In general, the online marketing process does not store any clear user data (such as e-mail addresses or names), only pseudonyms. This means that we as well as the providers of the online marketing procedures do not know the actual identity of the users, but only the information stored in their profiles.
As a rule, the information in the profiles is stored in the cookies or by means of similar procedures. These cookies can later be extracted and analysed for the purpose of presenting content on other websites that use the same online marketing procedure; they can also be supplemented with additional data and stored on the server of the online marketing procedure provider.
As an exception, clear data can be assigned to the profiles. This is the case, for example, if the users are members of a social network whose online marketing procedure we use and the network connects the profiles of the users in the aforementioned data. Please note that users can make additional agreements with the providers, e.g. by giving their consent during registration.
As a matter of principle, we only obtain access to summarised information on the performance of our advertisements. However, in the context of so-called conversion measurements, we can check which of our online marketing procedures have led to a so-called conversion, for example, to the conclusion of a contract with us. The conversion measurement is used solely to analyse the performance of our marketing measures.
Unless otherwise stated, we ask you to assume that cookies used are stored for a period of two years.
Notes on legal bases: If we ask users for their consent to use third-party providers, the legal basis for processing data is the provision of consent. Otherwise, users' data will be processed on the basis of our legitimate interests (i.e. interest in efficient, cost-effective and recipient-friendly services). In this context, we would also like to draw your attention to the information on the use of cookies in this privacy policy.
Definition of target groups with Google Analytics:We use Google Analytics in order to display the ads placed within the advertising services of Google and its partners only to those users who have also shown an interest in our online service or who exhibit certain characteristics (e.g. interests in certain topics or products determined by the websites visited), which we transmit to Google (so-called "remarketing" or "Google Analytics audiences"). With the help of remarketing audiences, we would also like to ensure that our ads match the potential interest of users.
Google Universal Analytics: We use Google Analytics in the form of Universal Analytics (https://support.google.com/analytics/answer/2790010?hl=de&ref_topic=6010376)."Universal Analytics" refers to a Google Analytics method in which user analysis is based on a pseudonymous user ID, thus creating a pseudonymous profile of the user with information from various devices (so-called "cross-device tracking").
Facebook Pixel: Facebook Pixel is designed to enable Facebook to determine the visitors of our online service as a target group for the presentation of ads (so-called "Facebook ads"). Accordingly, we use Facebook Pixel to display the Facebook ads placed by us only to those users on Facebook and within the services of partners cooperating with Facebook (so-called "Audience Network" https://www.facebook.com/audiencenetwork/ ) who have also shown an interest in our online services or who exhibit certain characteristics (e.g. interest in certain topics or products that can be seen from the websites visited) that we transmit to Facebook (so-called "Custom Audiences"). With the help of Facebook Pixel, we also want to make sure that our Facebook ads match the potential interests of users and are not annoying. Facebook Pixel also allows us to track the effectiveness of Facebook ads for statistical and market research purposes by establishing whether users were redirected to our website after clicking on a Facebook ad (so-called "conversion measurement").
Services and service providers used:
We maintain an online presence within social networks in order to communicate with the users active in such networks or to offer information about our company.
Please note that user data may be processed outside the European Union. This can result in risks for the users, because the enforcement of users' rights could be made more difficult. With regard to US providers that are certified under the privacy shield or offer comparable guarantees of a secure level of data protection, we would like to point out that they thereby undertake to comply with the data protection standards of the EU.
Furthermore, user data within social networks is generally processed for market research and advertising purposes. Thus, for example, user profiles can be created on the basis of user behaviour and the resulting interests of the users. The user profiles can in turn be used, for example, to place advertisements within and outside the networks that presumably correspond to the interests of the users. For these purposes, cookies are usually stored on users' computers, in which the usage behaviour and interests of the users are stored. Furthermore, data may also be stored in the user profiles independently of the devices used by the users (especially if the users are members of the respective platforms and are logged in to them).
For a detailed description of the respective forms of processing and the possibilities of objection (opt-out), we hereby refer to the data protection statements and information provided by the operators of the respective networks.
Also as regards requests for information and the assertion of data subject rights, we would like to point out that these can most effectively be asserted with the providers. Only the providers have access to the data of the users in each case and can directly take appropriate measures and provide information. Should you nevertheless require assistance, you can contact us.
Services and service providers used:
We integrate into our online service both functional and content-related elements that are obtained from the servers of their respective providers (hereinafter referred to as "third-party providers"). These can be, for example, graphics, videos or social media buttons as well as contributions (hereinafter uniformly referred to as "content").
Such integration always requires that the third-party providers of this content process the IP address of the users, as without the IP address they would not be able to send the content to their browser. The IP address is therefore required to display content or functions. We make every effort to use only such content for which the IP address is used by the respective providers solely for the purpose of delivering content. Third parties may also use so-called pixel tags (invisible graphics, also known as "web beacons") for statistical or marketing purposes. The "pixel tags" allow information such as visitor traffic on the pages of this website to be evaluated. The pseudonymous information may also be stored in cookies on the user's device and may contain technical information on the browser and operating system, websites to be referred to, the time of visit and other details on the use of our online service, as well as being linked to such information from other sources.
Notes on legal bases: If we ask users for their consent to use third-party providers, the legal basis for processing data is the provision of consent. Otherwise, users' data will be processed on the basis of our legitimate interests (i.e. interest in efficient, cost-effective and recipient-friendly services). In this context, we would also like to draw your attention to the information on the use of cookies in this privacy policy.
Services and service providers used:
We use the services, platforms and software of other providers (hereinafter referred to as "third-party providers") for the purposes of organising, managing, planning and providing our services. When selecting third-party providers and their services, we observe the legal requirements.
In this context, personal data may be processed and stored on the servers of the third-party providers. This may affect various data that we process in accordance with this privacy policy. This data may include, in particular, master data and contact details of users, data on procedures, contracts, other processes and their contents.
If users are referred to the third-party providers or their software or platforms in the course of communication, business or other relations with us, the third-party providers may process usage data and metadata for security purposes, service optimisation or marketing purposes. We therefore request that you observe the data protection notices of the respective third-party providers.
Notes on legal bases: If we ask users for their consent to use third-party providers, the legal basis for processing data is the provision of consent. Furthermore, their use can be a component of our (pre-)contractual services, provided that the use of third-party providers has been agreed in this context. Otherwise, users' data will be processed on the basis of our legitimate interests (i.e. interest in efficient, cost-effective and recipient-friendly services). In this context, we would also like to draw your attention to the information on the use of cookies in this privacy policy.
The data processed by us will be deleted, i.e. erased, in accordance with legal requirements as soon as consent given for processing is withdrawn or other permissions cease to apply (e.g. if the purpose for which the data was processed ceases to apply or if they are not necessary for the purpose).
Unless the data is erased because it is required for other and legally permissible purposes, its processing is limited to these purposes. This means that the data is blocked and not processed for other purposes. This applies, for example, to data that must be retained for reasons of commercial or tax law or that must be stored for the purpose of asserting, exercising or defending legal claims or protecting the rights of another natural or legal person.
Further information on the erasure of personal data can also be provided in the individual privacy policies of this data protection statement.
You are kindly requested to inform yourself regularly about the content of our data protection statement. We will adapt the data protection statement as soon as changes in the data processing carried out by us make this necessary. We will inform you as soon as the changes make it necessary for you to take action (e.g. to give your consent) or if any other form of individual notification is needed.
If we provide addresses and contact information of companies and organisations in this privacy policy, please note that the addresses may change over time and please check the information before contacting us.
As data subjects, you have various rights under the GDPR, arising in particular from Articles 15 to 18 and 21 GDPR:
This section provides an overview of the terms used in this data protection statement. Many of the terms are taken from the law and are defined above all in Art. 4 GDPR. The legal definitions are binding. The following explanations, on the other hand, are primarily intended to help you understand them.