We appreciate your interest in our company and your visit to our website. The protection of your privacy is very important to us. Below, we inform you in detail about how we handle your data.
1. Data protection at a glance
1.1 General notes
The following information provides a simple overview of what happens to your personal data when you visit this website. Personal data is any data with which you can be personally identified. Detailed information on the subject of data protection can be found in our privacy policy listed below this text.
1.2 Data collection on this website
How do we collect your data?
Your data is collected partly by you providing it to us. This may, for example, be data that you enter into a contact form. Other data is recorded automatically or with your consent by our IT systems when you visit the website. This is primarily technical data (e.g. internet browser, operating system or time of the page view). The collection of some data takes place automatically as soon as you enter this website.
What do we use your data for?
Some of the data is collected to ensure the error-free provision of the website. Other data may be used to analyse your user behaviour.
What rights do you have regarding your data?
You have the right at any time to obtain free information about the origin, recipient and purpose of your stored personal data. You also have the right to request the rectification or erasure of this data. If you have given consent to data processing, you can revoke this consent at any time for the future. You also have the right to request the restriction of the processing of your personal data under certain circumstances. Furthermore, you have the right to lodge a complaint with the competent supervisory authority.
You are welcome to contact us at any time regarding this and any other questions about data protection.
2. Hosting
We host our website with Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany.
When visiting our website, technically necessary data is processed by the hosting provider. This may include, in particular, IP addresses, the time and duration of access, pages or files accessed, browser and operating system information, and other technical connection data.
Processing is carried out for the purpose of the secure, stable and efficient provision of our online offering on the basis of Art. 6 (1) (f) GDPR. Our legitimate interest lies in the secure and reliable provision of our website.
Insofar as Hetzner processes personal data on our behalf, such processing is carried out on the basis of a data processing agreement in accordance with Art. 28 GDPR.
3. General notes and mandatory information
3.1 Data protection
As operators of these pages, we take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this privacy policy.
When you use this website, various personal data are collected. Personal data is data with which you can be personally identified. This privacy policy explains what data we collect and what we use it for. It also explains how and for what purpose this happens.
Please note that data transmission over the internet (e.g. via email communication) may be subject to security vulnerabilities. It is not possible to completely protect data against access by third parties.
3.2 Note on the controller
The party responsible for data processing on this website is:
Karl Püplichhuisen GmbH & Co. KG
20 Keniastraße
47269 Duisburg
Tel.: +49 203 99826 – 0
E-Mail: info@phuisen.de
3.3 Retention Period
Unless a more specific storage period has been specified in this privacy policy, your personal data will remain with us until the purpose for data processing ceases to apply. If you assert a justified request for erasure or revoke your consent to data processing, your data will be erased, provided we have no other legally permissible grounds for storing your personal data (e.g. retention periods under tax or commercial law); in the latter case, erasure will take place after these grounds cease to apply.
3.4 General information on the legal basis for data processing on this website
Provided you have consented to data processing, we process your personal data on the basis of Article 6(1)(a) GDPR or Article 9(2)(a) GDPR, provided that special categories of data are processed pursuant to Article 9(1) GDPR. In the case of explicit consent to the transfer of personal data to third countries, data processing is also carried out on the basis of Article 49(1)(a) GDPR.
Provided you have consented to the storage of cookies or to the access to information on your terminal device (e.g. via device fingerprinting), data processing is additionally carried out on the basis of Section 25(1) of the TDDDG. Consent can be revoked at any time.
If your data is required for the performance of a contract or for the implementation of pre-contractual measures, we process your data on the basis of Art. 6(1)(b) GDPR. Furthermore, we process your data, provided this is necessary for compliance with a legal obligation, on the basis of Art. 6(1)(c) GDPR.
Data processing may also be carried out on the basis of our legitimate interests pursuant to Art. 6(1)(f) GDPR. The legal bases applicable in each individual case are set out in the following paragraphs of this privacy policy.
3.5 Data Protection Officer
We have appointed a data protection officer; you can reach them at:
Karl Püplichhuisen GmbH & Co. KG
1. Attn: Data Protection Officer
20 Keniastraße
47269 Duisburg
Tel.: +49 203 99826 – 0
Email: datenschutz@phuisen.de
3.6 Recipients of personal data
As part of our business activities, we work with various external bodies. In some cases, this also requires the transfer of personal data to these external bodies. We only pass on personal data to external bodies if this is necessary for the performance of a contract, if we are legally obliged to do so (e.g. passing on data to tax authorities), if we have a legitimate interest in the transfer pursuant to Art. 6 para. 1 lit. f GDPR, or if another legal basis permits the data transfer. When using
We only pass on personal data of our customers to data processors on the basis of a valid data processing agreement. In the case of joint processing, a joint controllership agreement is concluded.
3.7 Withdrawal of your consent to data processing
Many data processing operations are only possible with your explicit consent. You can revoke consent that has already been given at any time. The legality of the data processing carried out up to the revocation remains unaffected by the revocation.
3.8 Right to data portability
You have the right to have data that we process automatically on the basis of your consent or in fulfilment of a contract handed over to you or to a third party in a common, machine-readable format. If you request the direct transfer of the data to another controller, this will only be done to the extent that it is technically feasible.
3.9 Access, rectification and erasure
Under the applicable statutory provisions, you have the right at any time to free information about your stored personal data, its origin and recipients, and the purpose of the data processing, and, where applicable, a right to the rectification or erasure of this data. You can contact us at any time regarding this or if you have any further questions on the subject of personal data.
3.10 Right to restriction of processing
You have the right to request the restriction of the processing of your personal data. You can contact us at any time for this purpose. The right to restriction of processing exists in the following cases:
- If you contest the accuracy of your personal data stored by us, we generally require time to verify this. For the duration of the verification, you have the right to request the restriction of the processing of your personal data.
- If the processing of your personal data was or is unlawful, you may request the restriction of data processing instead of erasure.
- If we no longer require your personal data, but you need them for the establishment, exercise or defence of legal claims, you have the right to request the restriction of the processing of your personal data instead of erasure.
- If you have lodged an objection pursuant to Article 21(1) GDPR, a balancing of your and our interests must be carried out. As long as it has not yet been determined whose interests prevail, you have the right to request the restriction of the processing of your personal data.
Where you have restricted the processing of your personal data, such data may – with the exception of storage – only be processed with your consent or for the establishment, exercise or defence of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the European Union or of a Member State.
3.11 SSL or TLS encryption
For security reasons and to protect the transmission of confidential content, such as orders or enquiries that you send to us as the site operator, this site uses SSL or TLS encryption. You can recognise an encrypted connection by the fact that the address line of the browser changes from „http://“ to „https://“ and by the padlock symbol in your browser bar.
When SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.
4. Data collection on this website
4.1 Cookie Consent
We use Cookiebot on this website, a consent management platform for managing and documenting the consents of our website visitors. The provider is Usercentrics A/S, Havnegade 39, 1058 Copenhagen, Denmark.
Cookiebot enables you to decide on the use of cookies and comparable technologies that require consent when visiting our website, as well as to subsequently change or withdraw consents given.
As part of providing the consent management, technical information such as the website visited, browser language, user agent and IP address may be processed in particular. To document your selection, a consent ID and the respective consent status are also processed and stored.
Cookiebot is used to fulfil our legal obligations to obtain and demonstrate consent in accordance with Article 6(1)(c) GDPR in conjunction with Article 7(1) GDPR and the relevant provisions of the TDDDG.
Further information on data processing by Cookiebot/Usercentrics can be found in the provider's privacy policy.
4.2 Server Log Files
The provider of the pages automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are:
- Browser type and browser version
- operating system used
- Referrer URL
- Hostname of the accessing computer
- Server request time
- IP address
These data are not combined with other data sources.
The collection of this data is based on Art. 6 (1) (f) GDPR. The website operator has a legitimate interest in the technically error-free presentation and optimisation of their website.
Currently, the following cookies are in use (essential cookies for using the website by enabling basic functions such as page navigation and access to secure areas of the website. The website cannot function properly without these cookies.)
4.3 Contact form
If you send us enquiries via the contact form, your details from the enquiry form, including the contact data you provided there, will be stored by us for the purpose of processing the enquiry and in the event of follow-up questions. We will not pass on this data without your consent.
The processing of this data is based on Article 6(1)(b) GDPR, provided your request is related to the fulfilment of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the effective handling of enquiries addressed to us (Article 6(1)(f) GDPR) or on your consent (Article 6(1)(a) GDPR) if this has been requested; consent may be revoked at any time.
The data you enter in the contact form will be retained by us until you request its deletion, withdraw your consent to its storage, or the purpose for storing the data no longer applies (e.g. once your enquiry has been dealt with). Mandatory legal provisions – in particular retention periods – remain unaffected.
4.4 Enquiry by email, telephone or fax
If you contact us by email, telephone or fax, your enquiry, including all resulting personal data (name, enquiry), will be stored and processed by us for the purpose of handling your request. We will not pass on these data without your consent.
The processing of this data is based on Article 6(1)(b) GDPR, provided your request is related to the fulfilment of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the effective handling of enquiries addressed to us (Article 6(1)(f) GDPR) or on your consent (Article 6(1)(a) GDPR) if this has been requested; consent may be revoked at any time.
The data you sent to us via contact enquiries will remain with us until you ask us to delete it, revoke your consent for storage, or the purpose for data storage no longer applies (e.g. after your request has been processed). Mandatory statutory provisions – in particular statutory retention periods – remain unaffected.
4.5 Reporting channel pursuant to HinschG (Whistleblower Protection Act)
The provision and operation of the whistleblowing system in connection with the Whistleblower Protection Act is carried out by the external data protection officer and is based on the SaaS solution (Software as a Service) from the company 2B Advice GmbH, Bonn.
2B Advice acts in this capacity as an authorised sub-processor of the controller (Art. 4 No 8 and Art. 28 GDPR).
During use, the data is stored on Microsoft's servers. The cloud solution „Azure“ offered by Microsoft is used. Servers located exclusively within the EU are deployed. When used for an anonymised report, exclusively the case ID used and the answer to the captcha are processed.
The legal basis for processing personal data when using an anonymous report is Art. 6(1)(b) GDPR and additionally Art. 6(1)(a) GDPR if you provide your name, telephone number and / or email address when making the report.
5. Audio and video conferencing data processing
For communication with our customers, we use online conference tools, among others. The tools we use in detail are listed below. If you communicate with us via video or audio conference over the internet, your personal data will be collected and processed by us and the provider of the respective conference tool.
The conference tools thereby collect all data that you provide/use for the use of the tools (e-mail address and/or your telephone number). Furthermore, the conference tools process the duration of the conference, start and end (time) of participation in the conference, number of participants and other „context information“ in connection with the communication process (metadata).
Furthermore, the tool provider processes all technical data required to facilitate online communication. This includes, in particular, IP addresses, MAC addresses, device IDs, device type, operating system type and version, client version, camera type, microphone or loudspeaker, and the type of connection.
Where content is exchanged, uploaded or otherwise made available within the tool, this content is also stored on the tool providers’ servers. Such content includes, in particular, cloud recordings, chat/instant messages, voicemails, uploaded photos and videos, files, whiteboards and other information shared whilst using the service.
Please note that we do not have full control over the data processing carried out by the tools we use. Our options depend largely on the corporate policy of the respective provider. For further information on data processing by the conference tools, please refer to the privacy policies of the respective tools, which we have listed below this text.
5.1 Purpose and legal basis
The conference tools are used to communicate with prospective or existing contractual partners or to offer specific services to our customers (Article 6(1)(b) of the GDPR). Furthermore, the use of these tools serves to generally simplify and speed up the
Communication with us or our company (legitimate interest within the meaning of Article 6(1)(f) of the GDPR). Where consent has been sought, the relevant tools are used on the basis of that consent; consent may be withdrawn at any time with future effect.
5.3 Retention Period
Data collected directly by us via video and conferencing tools is deleted from our systems as soon as you request its deletion, withdraw your consent to its storage, or the purpose for storing the data no longer applies. Stored cookies remain on your device until you delete them. Any mandatory statutory retention periods remain unaffected.
We have no control over how long your data is stored by the operators of the conferencing tools for their own purposes. For further details, please contact the operators of the conferencing tools directly.
5.4 Tool used
We use Microsoft Teams. The provider is Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. For details on data processing, please refer to the Microsoft Teams Privacy Statement: https://privacy.microsoft.com/de-de/privacystatement.
The company holds certification under the „EU-US Data Privacy Framework“ (DPF). The DPF is an agreement between the European Union and the US designed to ensure compliance with European data protection standards when data is processed in the US. Every company certified under the DPF undertakes to comply with these data protection standards. Further information on this is available from the provider via the following link: https://www.dataprivacyframework.gov/s/participant-search/participantdetail?contact=true&id=a2zt0000000KzNaAAK&status=Active
5.5 Data processing on behalf of a client
We have entered into a data processing agreement (DPA) for the use of the service mentioned above. This is a contract required under data protection law, which ensures that the service provider processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.
6. Our own services
6.1 Handling of applicants’ data
We offer you the opportunity to apply for a job with us (e.g. by email or post). Below, we provide information on the scope, purpose and use of your personal data collected as part of the application process. We assure you that the collection, processing and use of your data will be carried out in accordance with applicable data protection legislation and all other statutory provisions, and that your data will be treated in the strictest confidence.
6.2 Scope and purpose of data collection
If you submit an application to us, we will process your associated personal data (e.g. contact and communication details, application documents, notes taken during interviews, etc.) to the extent necessary to decide whether to establish an employment relationship. The legal basis for this is Section 26 of the German Federal Data Protection Act (BDSG) (pre-employment proceedings), Article 6(1)(b) of the GDPR (general pre-contractual arrangements) and – provided you have given your consent – Article 6(1)(a) of the GDPR. Consent may be withdrawn at any time. Your personal data will be disclosed within our company exclusively to those persons involved in processing your application.
Should your application be successful, the data you have submitted will be stored in our data processing systems in accordance with Section 26 of the German Federal Data Protection Act (BDSG) and Article 6(1)(b) of the General Data Protection Regulation (GDPR) for the purpose of managing the employment relationship.
6.3 Data retention period
If we are unable to make you a job offer, if you decline a job offer or if you withdraw your application, we reserve the right to retain the data you have provided, on the basis of our legitimate interests (Article 6(1)(f) of the GDPR) for up to 6 months from the end of the application process (rejection or withdrawal of the application). The data will then be deleted and the physical application documents destroyed. The data is retained in particular for evidential purposes in the event of a legal dispute. If it becomes apparent that the data will be required after the expiry of the 6-month period (e.g. due to an impending or pending legal dispute), the data will not be deleted until the purpose for its continued retention no longer applies.
Data may also be retained for a longer period if you have given your consent (Article 6(1)(a) of the GDPR) or if statutory retention obligations prevent its erasure.
6.4 Inclusion in the candidate pool
If we do not make you a job offer, there may be the option of adding you to our candidate pool. Should you be added to the pool, all documents and details from your application will be transferred to the candidate pool so that we can contact you should suitable vacancies arise.
Inclusion in the candidate pool is based solely on your explicit consent (Article 6(1)(a) of the GDPR). Giving your consent is voluntary and has no bearing on the ongoing recruitment process. The data subject may withdraw their consent at any time. In this case, the data will be irrevocably deleted from the candidate pool, provided there are no legal grounds for retaining it.
Data from the candidate pool will be permanently deleted no later than two years after consent is given.
7. Social media
7.1 Data processing by social networks
We maintain publicly accessible profiles on social media platforms. You can find a list of the specific social media platforms we use below. Social media platforms can generally analyse your user behaviour in detail when you visit their website or a website featuring integrated social media content (e.g. ‘Like’ buttons or advertising banners). Visiting our social media pages triggers numerous data-processing operations relevant to data protection. Specifically: if you are logged into your social media account and visit our social media page, the operator of the social media portal may associate this visit with your user account. However, your personal data may also be collected in certain circumstances even if you are not logged in or do not have an account with the relevant social media portal. In this case, data is collected, for example, via cookies that are stored on your device.
7.2 Collection of your IP address
Using the data collected in this way, the operators of social media platforms can create user profiles that record your preferences and interests. This enables interest-based advertising to be displayed to you both on and off the respective social media platform. If you have an account with the relevant social network, interest-based advertising may be displayed on all devices on which you are logged in or have previously been logged in. Please also note that we are not able to track all data processing activities on social media platforms. Depending on the provider, further processing operations may therefore be carried out by the operators of the social media platforms. For details, please refer to the terms of use and privacy policies of the respective social media platforms.
7.3 Legal basis
Our social media accounts are intended to ensure the most comprehensive online presence possible. This constitutes a legitimate interest within the meaning of Article 6(1)(f) of the GDPR. The analytical processes initiated by the social media platforms may be based on different legal grounds, which must be specified by the operators of those platforms (e.g. consent within the meaning of Article 6(1)(a) of the GDPR).
7.4 Data controller and exercising rights
When you visit one of our social media pages, we are jointly responsible with the operator of the social media platform for the data processing operations triggered by that visit. You may, in principle, exercise your rights (right of access, rectification, erasure, restriction of processing, data portability and the right to lodge a complaint) both against us and against the operator of the relevant social media platform. Please note that, despite our joint responsibility with the social media platform operators, we do not have full control over the data processing operations carried out by the social media platforms. Our options are largely determined by the corporate policy of the respective provider.
7.5 Retention period
Data collected directly by us via our social media presence will be deleted from our systems as soon as you request its deletion, withdraw your consent to its storage, or the purpose for which the data was stored no longer applies. Stored cookies remain on your device until you delete them. Mandatory legal provisions – in particular retention periods – remain unaffected. We have no influence over the duration for which your data is stored by the operators of social networks for their own purposes. For further details, please contact the operators of the social networks directly (e.g. in their privacy policy, see below).
7.6 Your rights
You have the right at any time to obtain, free of charge, information about the source, recipients and purpose of your stored personal data. You also have the right to object, the right to data portability and the right to lodge a complaint with the relevant supervisory authority. Furthermore, you may request the rectification, restriction, erasure and, under certain circumstances, the restriction of the processing of your personal data.
8. Social media in detail
8.1 LinkedIn
We have a profile on LinkedIn. The provider is LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland. LinkedIn uses advertising cookies. If you wish to disable LinkedIn advertising cookies, please use the following link: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out. Data transfers to the USA are based on the European Commission’s Standard Contractual Clauses. Further details can be found here: https://www.linkedin.com/legal/l/dpa and
https://www.linkedin.com/legal/l/eu-sccs. For details on how LinkedIn handles your personal data, please refer to LinkedIn’s privacy policy: https://www.linkedin.com/legal/privacy-policy. .
The company holds certification under the „EU-US Data Privacy Framework“ (DPF). The DPF is an agreement between the European Union and the US designed to ensure compliance with European data protection standards when data is processed in the US. Every company certified under the DPF undertakes to comply with these data protection standards. Further information on this is available from the provider via the following link: https://www.dataprivacyframework.gov/participant/5448