Privacy Policy
Data protection information for the Heraeus career portal (https://jobs.heraeus.com/)
Heraeus attaches great importance to data protection. Therefore, Heraeus processes your personal data exclusively within the framework of the statutory provisions and in compliance with appropriate technical and organizational data security measures.
1 General
1.1 Goals and responsibilities
(1) The purpose of this data protection notice is to inform you about the type, scope and purpose of the processing of personal data in our Heraeus career portal and the associated functionalities and content. The data protection information applies regardless of the domains, systems, platforms and devices (e.g. desktop or mobile) on which the Heraeus career portal is made available.
(2) The controller responsible for processing your data in the context of the application process is Heraeus Holding GmbH, Heraeusstraße 12-14, 63450 Hanau, Germany.
(3) You can contact our data protection officer at the following e-mail address: datenschutzbeauftragter@heraeus.com or by post:
Data Protection Officer
c/o Heraeus Business Solutions GmbH
Heraeusstr. 12-14
63450 Hanau, Germany
(4) The term "user" includes all registered users of the Heraeus career portal.
(5) Heraeus will only request data from persons under the age of 18 if these persons apply for a job, apprenticeship, internship for high school students, dual study program or working student internship at Heraeus via the Heraeus career portal. The data requested will be used exclusively for the purpose of the application process. It will not be used for any other purpose and will be deleted after completion of the application process in accordance with data protection requirements.
1.2 Legal basis
Your personal data is collected and processed on the following legal bases:
- Consent pursuant to Art. 6 para. 1 lit. a General Data Protection Regulation (GDPR). Consent is a declaration of intent that is given voluntarily in a specific case in an informed and unambiguous manner in the form of a declaration or other unambiguous confirmatory act if the data subjects make it clear that they consent to the processing of their personal data.
- Necessity for the fulfillment of a contract or for the implementation of pre-contractual measures pursuant to Art. 6 para. 1 lit. b GDPR, i.e. the data is necessary for us to fulfill our contractual obligations towards users, or we need the data to prepare a contract with users. In addition, where necessary, we process personal data to establish, implement or terminate an employment relationship in accordance with Section 26 BDSG.
Processing to safeguard legitimate interests in accordance with Art. 6 para. 1 lit. f GDPR, i.e. processing is necessary to safeguard our legitimate interests or those of a third party, provided that the interests do not outweigh the fundamental rights and freedoms of users who require the protection of personal data.
1.3 Rights of the data subject
You can assert your rights as a data subject in relation to your processed personal data at any time by contacting the Data Protection Officer using the contact details provided above. As a data subject, you have the following rights.
(1) Right to withdraw consent: If personal data is processed on the basis of consent, you have the right to withdraw this consent at any time for the future in accordance with Art. 7 GDPR.
(2) Right to information: In accordance with Art. 15 GDPR, you can request confirmation as to whether your data is being processed. If this is the case, you have the right to free information about the information.
(3) Right to rectification: If personal data has been processed while it was incorrect, you have the right to demand the correction of this data without delay in accordance with Art. 16 GDPR.
Make sure that the personal data you provide is truthful, correct, clear and up-to-date. It is your responsibility to keep the data entered in the system up to date.
In your profile you have the option of correcting your data yourself to ensure that it is up to date.
(4) Right to erasure: If you have withdrawn your consent, objected to the processing of your personal data (and there are no overriding legitimate grounds for the processing), your personal data is no longer required for the original purpose of processing, there is a corresponding legal obligation or personal data has been processed unlawfully, you have the right to request the erasure of your personal data in accordance with Art. 17 GDPR. You have the right to delete your registered user profile yourself at any time. You can do this yourself under the settings in your user profile after you have logged in with your registered data.
Please ensure that you withdraw your application(s) before deleting your profile. Deleting the user profile without withdrawing applications beforehand only deletes the user profile and does not automatically delete any open applications.
(5) Right to restriction of processing: In accordance with the provisions of Art. 18 GDPR, you have the right to request the restriction of the processing of your personal data.
(6) Right to data portability: In accordance with Art. 20 GDPR, you have the right to receive the personal data you have provided to us in a structured, commonly used and machine-readable format.
(7) Right to object: If the processing of personal data is necessary to safeguard the legitimate interests of our company, you can object to the processing at any time in accordance with Art. 21 GDPR.
(8) Right to lodge a complaint: In accordance with Art. 77 GDPR, you have the right to lodge a complaint with the competent supervisory authorities.
1.4 Deletion of data
Your personal data will be deleted as soon as the purpose for which it was collected no longer applies and there are no other statutory or contractual retention obligations.
You have the right to delete your registered user profile yourself at any time. As described in section 1.3 (4), you can do this in the settings. This will result in the entire user account being deleted. Please ensure that you withdraw your application(s) before deleting your profile. Deleting the user profile without withdrawing applications beforehand only deletes this profile and does not automatically delete any applications that are still open.
1.5 Security measures
State-of-the-art organizational and technical security measures are in place to ensure compliance with the relevant legal provisions and to protect personal data against accidental or intentional manipulation, loss, destruction or access by unauthorized persons.
1.6 Disclosure of data to third parties and third-party providers
(1) Heraeus transmits data to third parties exclusively within the framework of the statutory provisions. We only transfer user data to third parties if this is necessary or for other purposes that are required to fulfill our contractual obligations to users or legal requirements.
(2) Insofar as we use subcontractors to provide our services, we take appropriate legal precautions as well as technical and organizational measures to protect personal data in accordance with the applicable legal provisions.
(3) If we use content, tools or resources from other providers (hereinafter collectively referred to as "third-party providers") based in a third country as part of this privacy policy, it can be assumed that data will be transferred to such third countries.
(4) Third countries are countries in which the GDPR does not apply directly, i.e. basically all countries outside the EU or the European Economic Area. Data may only be transferred to third countries if an adequate level of data protection is guaranteed, you have given your consent, or the transfer of such data is permitted by law.
1.7 Obligation to provide personal data
(1) In principle, there is no legal or contractual obligation for you as a user to provide us with your personal data. The provision of your personal data via the Heraeus career portal is voluntary. However, the following information requested during registration and online application is marked as mandatory.
(2) Mandatory information when creating a user account:
- First name
- Surname
- E-mail address
- Country/region of residence
- Visibility of the profile
(3) Additional mandatory information in the profile information for an application:
- Salutation
- Contact details (address, telephone number, private cell phone number)
- Information about valid work permit
- Curriculum vitae (content determined by the applicant)
- Cover letter (only relevant for trainees)
- Last school report (only relevant for trainees)
- Penultimate school report (only relevant for trainees)
(4) If these fields are not completed, registration cannot take place, an application cannot be submitted and processed by Heraeus and therefore cannot be considered in the selection process.
1.8 Automated individual decision-making
We do not intend to use your personal data for automated decision-making processes (including profiling).
2 Data processing in detail
2.1 Data processing when visiting this website
(1) When you access our Heraeus career portal, information is automatically transmitted to us by your browser. This includes the date and time of access, the amount of data transferred, reports on successful access, the browser type and version, your operating system, the referrer URL (the page you visited before visiting our Heraeus career portal), your IP address and the requesting provider.
(2) The processing of your personal data is technically necessary in order to be able to offer you our Heraeus career portal as a service and is based on our legitimate interests pursuant to Art. 6 para. 1 lit. f GDPR with regard to the operation of the Heraeus career portal.
(3) The collection and storage of your personal data in log files is necessary for the provision of the Heraeus career portal for reasons of security and performance. For this reason, you cannot request the deletion or correction of this data or object to its processing.
2.2 Use of cookies
(1) We only use non-essential cookies if you give your express consent (opt-in) in accordance with Art. 5 (3) of Directive 2002/58/EC (also known as the "ePrivacy Directive", hereinafter "ePD") and the respective national law that implements Art. 5 (3) ePD, e.g. Section 25 of the Telecommunications Digital Services Data Protection Act (TDDDG). If you do not want cookies or other information to be stored on your computer, you can also deactivate the corresponding option in the system settings of your browser. Stored cookies and other information can also be deleted in the browser's system settings. Deactivating cookies and other information can lead to functional restrictions on this website.
(2) If you have consented to the storage of cookies and information on your device or access to information stored on your device, both activities will be carried out on the basis of section Art. 5 (3) ePD.
(3) We obtain users' consent to the use of cookies and other information on all websites within the domain heraeus.com.
(4) You can change your cookie settings here.
2.3 Google Analytics
(1) The Heraeus career portal uses functions of the web analysis service Google Analytics either directly in your browser (client-side tracking) or indirectly on our web server (server-side tracking). The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (hereinafter referred to as "Google"). Google Analytics enables the website operator to analyze the behavior of website visitors.
(2) The website operator receives various usage data, such as page views, length of visit, operating systems used and origin of the user. This data can be summarized by Google in a profile that is assigned to the respective users or their devices.
(3) The purpose of using Google Analytics is to enable the recognition of users for the purpose of analyzing user behavior through the use of various technologies (e.g. cookies or device fingerprinting). We use demographic characteristics for our analyses. The information collected by Google about the use of our website is usually transferred to a Google server in the USA and stored there.
(4) The use of Google Analytics is based on your consent in accordance with Art. 6 (1) (a) GDPR and section Art. 5 (3) ePD. Consent can be withdrawn at any time with effect for the future.
(5) We have concluded an order processing agreement (AVV) in accordance with Art. 28 GDPR for the use of the above-mentioned service.
(6) You can find details here: https://privacy.google.com/businesses/controllerterms/mccs/. You can object to the collection and storage of data at any time with effect for the future. You can object to the collection and storage of data by Google Analytics with effect for the future by downloading and installing the browser plug-in available at the following link: https://tools.google.com/dlpage/gaoptout.
(7) The data stored by Google at user and event level, which is linked to cookies, user identifiers (e.g. user ID) or advertising IDs, is anonymized or deleted after 14 months. Details can be found at the following link: https://support.google.com/analytics/answer/7667196
(8) For more information about Google's use of data as well as setting and opt-out options, please visit Google's websites: https://www.google.com/intl/de/policies/privacy/partners. ("Data use by Google when you use our partners' websites or apps"), https://www.google.com/policies/technologies/ads ("Data use for advertising purposes"), https://www.google.de/settings/ads ("Managing information that Google uses to show you advertising").
2.4 Processing of access data
(1) You must register to use the Heraeus career portal. Applications without a user account are not possible. When you register, we will ask you for various information that is important for opening a user account and handling the application process.
(2) The legal basis for this is Art. 6 para. 1 lit. b GDPR and § 26 BDSG, i.e. you provide us with the data on the basis of the contractual relationship or for the implementation of pre-contractual measures between you and us.
(3) Before you access the overview of our current vacancies, Heraeus provides information about careers on the website https://www.heraeus-group.com/de/careers/. You will be informed separately about data processing on this website.
2.5 Job Alert
(1) With our "Job Alert", we offer users of the Heraeus career portal the opportunity to be informed about job updates by e-mail.
(2) The legal basis for this is your consent (Art. 6 para. 1 lit. a GDPR).
(3) You can deactivate Job Alert by changing your settings. To do this, click on the "Manage My Alerts" link contained in every Job Alert email.
2.6 Processing of your application data
(1) We will not pass on your personal data to third parties. We will make your data available to the responsible employees. If you have consented to the disclosure to organizational units within the Heraeus Group, your data will be forwarded within the Heraeus Group as required.
The data you enter in the Heraeus career portal can be viewed by employees who are directly involved in filling the position (HR and line managers). Our employees are obliged to comply with data protection requirements.
(2) The personal data provided by you as part of an application process will be used to process the application process. This also includes information obtained in particular from subsequent interviews, tests, questionnaires or references.
After a successful application, the personal data will be transferred to your personnel file.
2.7 Duration of processing as part of the application process
If you have not logged into the system for 365 days, i.e. have not logged into your user account, and no application is active, your data will be automatically deleted by us. Data that you have sent to us with an application will be deleted after 200 days in an inactive status, e.g. after you have received a rejection. Of course, you can also delete or block your data yourself at any time before this period expires.
In the event of blocking, the data will not be deleted, but only not used until you release it again. In the event of deletion, the data will be permanently deleted and cannot be restored.
-
2.8 Data transmission to and data processing by external parties
(1) The data is hosted by the provider SAP in the "Successfactor" solution as part of order processing. We have concluded an order processing agreement (AVV) for the use of the service in accordance with Art. 28 GDPR.
(2) The service provider we use must meet special confidentiality requirements, so that we agree the security of your data with the service provider.
3 Get in touch with us
(1) When you contact us (via contact form or e-mail), we will store and process your request, including all resulting personal data (name, request, contact details) for the purpose of processing your request.
(2) This data is processed on the basis of Art. 6 para. 1 lit. b GDPR and Section 26 BDSG if the request is necessary in connection with the establishment, implementation and/or termination of an employment relationship. In all other cases, the processing is based on our legitimate interest in the effective processing of inquiries addressed to us (Art. 6 para. 1 lit. f GDPR) or on your consent (Art. 6 para. 1 lit. a GDPR).
4 Changes to the data protection information
(1) We reserve the right to amend the data protection information in order to adapt it to changes in the legal situation or to changes in our services and data processing. However, this only applies to data processing guidelines.
(2) If the user's consent is required or if elements of the data protection information contain elements of the contract agreed by the user, the changes will only be made with the user's consent.
(3) Users are requested to familiarize themselves regularly with the content of the data protection information.
Last update: 06.12.2024
Version: Bew.-Portal-2.0