Privacy policy
Privacy policy for employees
We would like to inform our employees about how we handle their personal data in the context of the employment relationship.
During the period of your employment, your personal data will be primarily processed for the execution and/or termination of the employment contract, including tasks related to the respective position. Other purposes may include processing for compliance with legal regulations (including third-party disclosure obligations) or measures for corporate development or communication.
Identification/payment data: ID card data or work permit for identification, birthplace, marital status, parentage, tax identification number, health insurance membership, tax class, deductions, religious affiliation for church tax, bank account number, any wage garnishments (for payroll and compliance with legal obligations).
Health data: e.g., for payroll, billing with health or accident insurance, or for legal obligations as an employer, such as company integration management or compliance with disability protection.
Time tracking, access, and usage data: Vacation times, working hours, time records regarding performed activities, closing times or access records, also electronic logs in the use of our IT infrastructure, etc.
Personnel screening data: e.g., criminal record, reliability check, or other necessary checks required for the activity for our clients.
Suitability and performance/behavior control data: Training and further education information, data for the purpose of measuring goal achievement (e.g., for variable compensation), data on violations of traffic regulations ("traffic tickets").
Other data in personnel administration: Secondary employment, data in the context of occupational health care and occupational health management, occupational safety, degree of disability, driver's license ownership, any employee surveys.
We transmit your personal data to the following recipients in order to fulfill legal obligations or obligations arising from the employment relationship:
Bank service providers, financial service providers, if necessary, service providers for calculating pension provisions:
Service providers for the settlement of wages (tax consultants), auditors, service companies for information and communication technology, companies for software and device maintenance, service providers only for restructuring in the personnel department:
Health, social, pension, and accident insurance carriers as well as other insurance companies and providers of asset-effective benefits:
Authorities such as financial authorities, social funds, employment agencies, if necessary, security, health, traffic or related fine offices, customs authorities or monitoring agencies for undeclared work and minimum wage; other authorities:
Company medical service:
Legally affiliated companies (group companies) as joint controllers: the essential contents of the regulation of tasks concerning the rights of data subjects can be requested at the specified contact address; according to Article 26 (3) GDPR, these rights can be claimed by data subjects from all involved companies.
Third-party debtors in the case of wage garnishment, insolvency administrators in the case of private insolvency:
Business partners and customers (business contact details), temporary employment agencies if they are working for us as part of temporary employment:
In the processing of your personal data, we naturally adhere to applicable laws. Therefore, processing only takes place on a legal basis. The following legal bases are particularly relevant in the employment relationship:
When processing your data within our legitimate interests, this may include:
You have the right to object to the processing of personal data based on legitimate interests for reasons arising from your particular situation. In such cases, we will no longer process your data unless we can demonstrate compelling legitimate grounds that override your rights and freedoms or if the processing serves the establishment, exercise, or defense of legal claims.
We do not use the personal data provided by you to make automated decisions concerning you.
Through the ELSTAM procedure, we collect data for payroll accounting provided by the tax authorities to ensure accurate accounting. This particularly involves the data mentioned above related to payroll.
Upon achieving the respective purpose, your data will be deleted in compliance with legal retention periods, usually 6 or 10 years, with various data categories such as professional pension planning retained for 30 years or longer.
We utilize a Mobile Device Management System (MDM) to manage the mobile devices provided to you during your employment with us. Mobile devices may include smartphones and laptops. An MDM system allows for device management by installing software on the device and connecting it to an administration platform. The IT department has access to this platform. The MDM system controls which apps can be downloaded or which websites can be visited (whitelisting and blacklisting). It uses containerization to separate private and business data, and remote access to the devices is possible. In cases of theft, this is a measure to erase personal data on the devices, protecting against unauthorized access. We primarily process the resulting personal data based on our legitimate interest under Art. 6(1)(f) GDPR.
Responsible for Processing Your Personal Data:
Cofinpro AG
Untermainkai 27-28
60329 Frankfurt am Main
Phone: +49 (0) 69 - 299 20 87 60
(Cost of a call at your regular landline/mobile rates / custo de chamada para a rede fixa nacional)
Fax: +49 (0) 69 - 299 20 87 61
Email: welcome@cofinpro.de
The legal basis for processing your personal data in the context of video surveillance includes:
Our legitimate interests include, but are not limited to:
The processing of personal data on the device is a result of securing the device for both private and business use, and it is not the main focus. Given the potential for apps that do not meet data protection requirements or may install viruses and capture personal data through private use, it is essential to protect the personal data generated during your work for our company. Therefore, measures such as containerization or black- and whitelisting are implemented.
Furthermore, it is crucial to protect this data from unauthorized access by third parties, especially in the event of device loss. To ensure security, remote access or remote deletion is possible. However, GPS tracking, which is a feature of the MDM system, is not implemented by us.
In the event of loss, we use the MDM system to delete business-relevant data on your device. Deletion of other private data is possible for you through the iCloud Portal function.
You have the right to:
We reserve the right to change our privacy policy as needed and publish it on this page. Please check this page regularly. The updated statement will come into effect upon publication, subject to applicable legal regulations. If we have already collected data about you that is affected by the change and/or is subject to legal information obligations, we will additionally inform you about significant changes to our privacy policy.