Jump to content

Privacy policy

We are glad you visit our website and that you are interested in MHP Consulting Romania SRL and in our services. Your privacy is an important concern to us. We handle the protection of your personal data and their strictly confidential processing with great care. Your personal data will be exclusively processed in compliance with the applicable provisions under data protection law.

In this Privacy Policy, we will inform you on the processing of your personal data and your rights under data protection law. Due to the ongoing technological further development, changes in our services or the legal situation, or other reasons, modifications or amendments of our Privacy Policy may be required. We reserve the right to update this Privacy Policy at any time and ask you to review the latest version at regular intervals.

1. DATA CONTROLLER AND DATA PROTECTION OFFICER; CONTACT

The Data Controller within the meaning of data protection laws, rules, and regulations is:

MHP Consulting Romania SRL
Onisifor Ghibu Street No. 20A | Building C4 | Floors 4, 5, 6
400185 Cluj-Napoca
Romania

Mobile: +40 732404621
email:  MhpdataprivacyRomania(at)mhp.com
Web:   www.mhp.com

Please do not hesitate to contact us if you should have any questions or suggestions regarding data protection issues.

You may contact our Data Protection Officer as follows:

Rareș Boca
Data Protection Officer

MHP Consulting Romania SRL
A Porsche Company
Office Cluj-Napoca
Onisifor Ghibu Street No. 20A | Building C4 | Floors 4, 5, 6
400185 Cluj-Napoca, Romania

Contact:

mhpdataprivacyromania@mhp.com
Mobile: +40 790013707

2. SUBJECT MATTER

The subject matter of this Privacy Policy is personal data.

“Personal data” means any information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.

Other than described in the sections below, no personal data will be collected, processed, or used during the visit of our website. When you visit our website, our web servers will automatically capture general information. This includes the type of web browser, the operating system used, the domain name of the internet service provider, IP address of the computer used, the referring website, the pages of our website that you visit and the date and duration of your visit.

We cannot use this data to identify individual users. We will only analyze this information for statistical purposes and for improving the attractiveness, contents, and functionality of our website.

3. LEGAL BASIS OF DATA PROCESSING

In the event we obtain a consent from a data subject for the processing of personal data, Art. 6, par. 1, lit. a of the European General Data Protection Regulation (GDPR) forms the legal basis for processing your personal data.

If the processing of personal data is necessary for performing an agreement to which the data subject is a party this is governed by Art. 6, par. 1, lit. b of the General Data Protection Regulation (GDPR). This shall also apply to processing steps that are required to carry out tasks prior to the conclusion of an agreement.

If the processing of personal data is necessary for meeting a statutory obligation to which our company is bound, Art. 6, par. 1, lit. c of the General Data Protection Regulation (GDPR) forms the legal basis.

In the event processing is necessary in order to protect the vital interests of the data subject or of another natural person, Art. 6, par. 1, lit. d of the General Data Protection Regulation (GDPR) forms the legal basis for processing your personal data.

If data processing is necessary for the purposes of the legitimate interests pursued by our company or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, Art. 6 par. 1 lit. f of the General Data Protection Regulation (GDPR) forms the legal basis for processing your personal data.

The passing on of your personal data within the Porsche Group for the purpose of responding to and forwarding inquiries is also subject to these statutory provisions.

4. DELETION OF DATA AND STORAGE PERIOD

Personal data of the data subject will be deleted or blocked as soon as the purpose of storage ceases to apply. Data may be stored beyond this period, if provided by EU regulations, national law, or other rules and regulations adopted by the EU or national legislators by which the controller is bound. Data will also be blocked or deleted when a storage period set forth in any of the indicated rules and regulations expires unless the further storage of data is required for the conclusion of a contract or contract performance.

5. COLLECTION AND PROCESSING OF PERSONAL DATA

Personal data will only be collected if you provide it upon your own request, e.g., as a participant of a survey or when registering for personalized services. In these cases, you will be notified of the intended storage purpose and, if necessary, asked to grant your consent to data storage.

Personal data collected in connection with our website will only be used for filling orders or processing your inquiries unless you grant your consent to other forms of processing.

Any other form of processing requires your prior consent.

This use of data is restricted to the purposes of advertising and market and public opinion research and this data will be exclusively available to MHP.

You may withdraw your consent to a particular type of use at any time with effect to the future.

Your data will not be sold, rented, or made available to third parties in any manner other than those described herein. Data transmission of personal data to state and public authorities will only be carried out subject to mandatory national statutory provisions. Our employees, agencies, and dealers have been bound to the duty of strict confidentiality.

5.1. CONTACT

You may contact us by writing to our email address. Of course, we will use any personal data provided to us this way only for the purpose for which it was made available during this contact.

To the extent that our contact form contains fields that are not required for contacting you, these fields are marked as optional fields. This information helps us to gather further details regarding your inquiry and improves the handling of your concern.

We expressly draw your attention to the fact that you provide your information on a voluntary basis and that you grant your consent to us using it. In the event this should concern information on other communication channels (for instance, email account, phone number), you also provide your consent that we may contact you that way in order to respond to your inquiry.

In addition, at the time of sending the message the following data will be stored:

IP address of user

date and time of registration

Data processing is not permissible unless you have granted your consent.

Your personal data will not be passed on to third parties in connection herewith. This data will only be used for processing the conversation. Of course, you may withdraw this consent at any time with effect to the future by writing to MhpdataprivacyRomania(at)mhp.com

5.2. JOB APPLICATIONS

You may apply for a job with MHP online using our recruiting platform. Your online application is transmitted directly to the HR department via an encrypted connection and will be treated in strict confidence. Of course, we will use your information only for processing your application and will not pass it on to third parties.

If you have applied for a particular position and this position is has been filled or if we believe that you are similarly or even better suited for another position, we would like to pass on your application within the Porsche Group. In the course of the application process you may determine on the entry screen whether you agree with this forwarding or not.

Your personal data will be immediately deleted upon the completion of the application process or upon the expiration of a period of six (6) months unless you have granted your express consent to a longer storage period of your data.

Please note that we accept job applications only through our recruiting platform. If you should apply by email anyway, we expressly draw your attention to the fact that email attachments are not encrypted.

5.3. NEWSLETTER

You may subscribe to our free newsletter on our website. When you register for our newsletter, the information provided on screen will be transmitted to us.

The processing of data obtained through a user’s registration for a newsletter is governed by Art. 6, par 1, lit. a of the GDPR, if the user has granted his/her consent.

If you acquire goods or services through our website and enter your email account for this purpose, we have the right to use this address for mailing a newsletter afterwards. In this case, the newsletter will only contain direct marketing contents for similar goods or services provided by us.

No data will be passed on to third parties in connection with data processing for newsletter mailings. This data will only be used for mailing the newsletter.

In addition, the following information will be collected at the time of registration:

IP address of requesting computer

date and time of registration

The user may unsubscribe from the newsletter at any time. Each newsletter will contain a link for this purpose.

By clicking this link, the user may withdraw his/her consent to storing the personal data that was collected during the registration process to take effect in the future.

5.4. REGISTRATION

Our website allows users to register by entering personal data. The user’s registration is required for providing certain contents and services on our website. We need your registration information in order to be able to send you your login data or event information.

Data processing is not permissible unless you have granted your consent.

You need to enter your data on screen and this information will be transmitted to and stored by us. Data will not be passed on to third parties. The following data will be collected during the registration process:

Company Position Department Form of address First name Family name Street Number Zip code Place Country Phone Fax Email

In addition, at the time of registration the following data will be stored:

IP address of user

date and time of registration

Of course, you may withdraw this consent any time with effect to the future by writing to MhpdataprivacyRomania(at)mhp.com

5.5. TELEPHONE CONTACT

In the event that we initially contact you by phone, we have generated your data from public sources. Our interest in the initial telephone contact overrides the interest of the data subject, since we exclusively contact B2B customers via contact channels available from public sources and the contact refers to specific processes in connection with the business activity of the person concerned. During this initial phone call, we will merely inquire whether this particular person is interested in establishing a contact with MHP and do not comprehensively present our services.

5.6. PROVISION OF WEBSITE AND GENERATION OF LOGFILES

During each visit of our web pages, our system will automatically collect data and information from the retrieving computer system. The following information will be collected:

Information on the browser type and the version used

User’s operating system

User’s internet service provider (ISP)

IP address of user

date and time of access

Websites from which user’s system is referred to our website

Websites that the user’s system calls up through our website

This information will also be stored in the logfiles of our system. This information will not be stored together with other personal data of the user.

The temporary storing of data and logfiles is governed by Art. 6, par 1, lit. f of the GDPR.

The IP address needs to be temporarily stored by the system in order to allow the delivery of the website to the user’s computer. To this end, the IP address of the user needs to be stored during the entire session.

This information will be stored in logfiles in order to ensure the operability of the website. In addition, this data helps us to optimize our website and to ensure the security of our IT systems. This information will not be analyzed for marketing purposes. We have a legitimate interest in data processing for these purposes pursuant to Art. 6, par. 1, lit. f of the GDPR.

Data will be deleted as soon as it is no longer needed for attaining the purpose for which it was collected. With regard to the collection of data for the purpose of making the website available this is the case when the session concerned is over.

In the event data is stored in logfiles, data will be deleted no later than within seven (7) days. It is possible to store data for a longer period. In this case, the IP addresses of the users will be deleted or pseudonymized so that the retrieving software client may no longer be assigned to an individual.

6. WEBSITE OPTIMIZATION TOOLS

With regard to the collection of personal data using website optimization tools we refer to our legitimate interest pursuant to Art. 6, par. 1, lit f. GDPR in connection with recital no. 47. In accordance herewith, direct marketing purposes usually constitute a legitimate interest. Your interests, basic rights and fundamental freedoms do not override our interest in advertising since we comprehensively inform you in our Privacy Policy about the data collection and you have the possibility of opting-out (via link or browser settings) at any time. In addition, we only use pseudonymized tracking.

6.1. COOKIES

Our website uses both session cookies and permanent cookies. Session cookies are temporary cookies that are stored on the web browser of a user until the browser window is closed and, thus, the session cookies are deleted. Permanent cookies are used for return visits and will be stored in the user’s browser for a certain period (usually one (1) year or longer). These cookies are not deleted when the browser software is closed. This type of cookies will be used to reuse the user’s preferences once they return to our web page.

We use cookies on our website that allow us to analyze the user’s surfing behavior. This way, the following data can be transmitted:

Search terms entered

Frequency of page views

Use of website features

User data collected this way may be pseudonymized by design. This means, data may not be linked with the viewing user. This type of data will not be stored together with other personal data of the users. When viewing our website, a banner cookie will inform users on the use of cookies for analytical purposes and reference to the Privacy Policy will be made. In this regard, we will also provide information on how to prevent the storage of cookies through browser settings.

When viewing our website, the user will be informed about the use of cookies for analytical purposes.

Of course, you may also view our website without allowing cookies. If you do not wish cookies to be stored on your computer, you may disable the corresponding option in the system settings of your browser. Stored cookies can be deleted in the system settings of your browser any time. For further details please refer to the user manual provided by the producer of your browser software. Please note, however, that our web presence may not be fully available without the use of cookies.

6.2. MATOMO

This website uses the web analysis tool Matomo. Matomo uses so-called "cookies" (see point 6.1) to compile reports on website activities and to evaluate your use of the website. The aim is to be able to optimize the internet presence further.

To be able to evaluate the usage behaviour, the information about the usage received by the "cookie" is transferred to our servers and stored for usage analysis purposes. Your IP address is anonymized immediately after processing, which means that you, as a user, remain anonymous. The information generated by the "cookie" about the use of the website is not passed on to third parties.

7. DATA TRANSMISSION

Data transmission to other group companies

Generally, your data will not be transmitted to third parties outside MHP, unless this is a mandatory statutory duty or if this data transmission is required for performing the contract or if you have granted your express prior consent. External service providers and partner companies will only receive your data to the extent necessary to process your inquiry. However, in these events, the scope of data transmitted will be restricted to the necessary minimum amount of data. To the extent that our service providers have access to your personal data, we shall ensure that these will comply with the data protection law, rules, and regulations in the same manner. Please note the corresponding privacy policies of these service providers. The corresponding service provider is responsible for the contents of third-party services, provided, however, that we will monitor the services for their compliance with statutory provisions to the extent reasonable.

Data transmission to external service providers (processors)

Your data will be forwarded to service providers that perform services on our behalf and assist MHP in the provision of its services.

If your personal data is processed by commissioned service providers, these activities will be carried out within the scope of data processing pursuant to Art. 28 of the GDPR. The service providers referred to above will only be granted access to such personal data that is needed for performing the corresponding tasks. These service providers are not allowed to pass on your personal data or to use it for any other purpose, in particular, for their own advertising or marketing purposes.

To the extent that external service providers have access to your personal data, we have ensured by legal measures, privacy by default and by design, and through regular reviews and inspections that they will comply with the applicable data protection laws, rules, and regulations.

Your personal data will not be transmitted to other companies for commercial purposes.

Integration of YouTube

We use YouTube, a service of Google Ireland Ltd, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland, for video embedding. Legal basis for the embedding is Art. 6 (1)(a) GDPR. The content of YouTube is not downloaded until you have given your approval. The YouTube videos are integrated in the YouTube code with deactivated tracking functions. For more information, please visit the detailed privacy policy of Google at: https://www.google.com/policies/privacy/, Opt-Out: https://adssettings.google.com/authenticated. A data transfer to the USA shall only be carried out if the requirements of Articles 44 et seqq. GDPR are fulfilled.

8. DATA SECURITY

We use technical and organizational safeguards (privacy by default and by design) to protect your personal data against coincidental or willful manipulation, loss, destruction or access by unauthorized parties. Our security measures will be continuously improved based on the state of the art.

9. RIGHTS OF THE DATA SUBJECT

If your personal data is processed, you are a “data subject” within the meaning of the GDPR and you are entitled to the following claims against the “controller”:

Right of access pursuant to Article 15 of the GDPR
You have the right to obtain from us confirmation as to whether or not personal data concerning you is being processed. If we have processed your personal data, you are entitled to further rights to access set forth in Article 15 of the GDPR.

Right to rectification
If data that we collected on you is inaccurate or incomplete, you may claim the rectification without undue delay pursuant to Article 16 of the GDPR.

Right to restriction of processing
Subject to Article 18 GDPR, you may also have the right to claim the restriction of processing of personal data concerning you. Where processing has been restricted, your personal data shall only be processed with your consent or for the assertion, exercise or defense of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the Union or of a Member State. We will notify you before the restriction is lifted.

Right to erasure
If one or more of the grounds listed in Article 17 par. 1 of the GDPR apply, you may claim the erasure of personal data concerning you without undue delay, unless there is an exception pursuant to Article 17, par. 3 of the GDPR.

Right to notification
If you have asserted the right to rectification, erasure of personal data, or restriction of processing, we are obligated pursuant to Article 19 of the GDPR to notify all recipients to whom personal data has been disclosed, unless this proves impossible or involves disproportionate effort. In addition, you have the right to be informed about who these recipients are. You may exercise your right to be informed of those recipients against the controller.

Right to data portability
Furthermore, pursuant to Article 20 of the GDPR, you have the right to receive the personal data concerning you in machine readable format and to transmit this data to another controller without hindrance, provided, however, that the conditions enumerated in Article 20, par. 1, lit. a of the GDPR exist or to demand to have the personal data transmitted directly from us another controller, where technically feasible and if this does not adversely affect the rights and freedoms of others. This right shall not apply to processing of personal data necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.

Right to object
You have the right to object at any time to processing of personal data concerning you by written notice to MHP which is based on Article 6, par 1, lit. f of the GDPR. We shall not longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms or if the processing serves the assertion, exercise or defense of legal claims.

Right to withdraw the consent under data protection law, rules, and regulations
You may withdraw your data protection consent at any time by notifying MHP. The withdrawal of your consent shall not affect the lawfulness of processing based on this consent prior to its withdrawal.

Right to lodge complaints with the supervisory authority:
Furthermore, you have the right to lodge a complaint with the competent supervisory authority, if you consider that the processing of your personal data violates the applicable statutory provisions, rules, and regulations. In this case, you may contact the Data Protection Authority having competence at your place of residence or in your country or the Data Protection Authority having competence at our place of business.

How to contact us or to exercise your rights:
Furthermore, if you should have any questions on the processing of your personal data, your rights as a data subject, or any consent that may have been granted, you may contact us free of charge. If you wish to exercise any or all of your rights, please email us at info@mhp.com or write a letter to the address set forth in section 1 above.

10. MODIFICATONS AND AMENDMENTS

This Privacy Policy will be modified and/or amended when the internet or our web offering change. We will notify you of any updates on this page in due time. In order to stay informed on the current version of our Privacy Policy, please visit this web page at regular intervals.

This Privacy Policy shall apply as amended. Last revised: 5/24/2018

Privacy policy for existing customers

Welcome to our website and thank you for your interest in MHP Consulting Romania SRL and in our services. Your privacy is an important concern to us. We exercise great care in the protection of your personal data and their strictly confidential processing. Your personal data will be exclusively processed in compliance with the applicable provisions under data protection law, rules, and regulations.

In this Privacy Policy, we will inform you about the processing of your personal data and your data protection rights within the scope of our business relationship.

Due to the ongoing technological further development, changes in our services or the legal situation, or other reasons, modifications or amendments of our Privacy Policy may be required. We reserve the right to update this Privacy Policy at any time and ask you to review the latest version at regular intervals.

1. DATA CONTROLLER AND DATA PROTECTION OFFICER; CONTACT

The Data Controller within the meaning of data protection laws, rules, and regulations is:

MHP Consulting Romania SRL
Onisifor Ghibu Street No. 20A | Building C4 | Floors 4, 5, 6
400185 Cluj-Napoca
Romania

mobile: +40 732404621
email:  MhpdataprivacyRomania(at)mhp.com

Please do not hesitate to contact us if you should have any questions or suggestions regarding data protection issues.

You may contact our Data Protection Officer as follows:

Rareș Boca
Data Protection Officer

MHP Consulting Romania SRL
A Porsche Company
Office Cluj-Napoca
Onisifor Ghibu Street No. 20A | Building C4 | Floors 4, 5, 6
400185 Cluj-Napoca, Romania

Contact:

mhpdataprivacyromania@mhp.com
Mobile: +40 790013707

2. SUBJECT MATTER

The subject matter of this Privacy Policy is personal data.

“Personal data” means any information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.

This shall include data such as the name, email account, phone number, position and/or role, but also any other information that may be relevant when negotiating or in the course of a business relationship.

3. COLLECTION AND PROCESSING OF PERSONAL DATA

We will give you an overview of the purposes and legal basis of data processing within the scope of our business relationship in the sections below.

3.1 DATA PROCESSING FOR A CONTRACTUAL RELATIONSHIP

We process personal data if this is required for preparing and performing the contract concluded with you. The purposes depend on the particular contract, and include, in particular, the necessary measures prior to contract conclusion, the answering of your related questions, the transmission of offer and project status and invoicing information, the communication in the course of contract performance, the processing of contracts concluded, andcustomer service prior, during and after the business relationship we with you.

Data processing is permissible, if this processing occurs in connection with the purpose of the contract.

For further details on the purposes of data processing please refer to the contract documents.

Your data will be processed pursuant to Art. 6, par. 1, lit. b of the GDPR. In this regard, you will need to provide any personal data that we need for preparing and carrying out our business relationship with you. In the absence of this information, we will not be able to process your inquiry and/or to perform the contract.

We will delete your personal data if this personal data is no longer needed for negotiating and conducting a business relationship with you and if this deletion does not conflict with statutory retention periods.

3.2 DATA PROCESSING DUE TO STATUTORY REQUIREMENTS

We will also process your personal data for the purpose of compliance with statutory requirements that apply to us. These requirements may exist under the trade, tax, money laundering, financial, or criminal code. The processing purposes are determined by the applicable statutory duty; generally, data processing will only serve the purpose of compliance with monitoring and disclosure duties under national law.

Your data will be processed pursuant to Art. 6, par. 1, lit c. of the GDPR. If we collect data in compliance of a legal obligation, you will need to provide any personal data that we need to comply with our legal obligation. In the absence of this information, we may not be able to process your inquiry.

We will delete your personal data when the legal obligation to store your data ceases to exist, provided, however, this deletion does not conflict with statutory retention periods.

3.3 DATA PROCESSING DUE TO LEGITIMATE INTEREST

We will also process personal data for the purposing of exercising our own legitimate interests or those of third parties. The legitimate interests, which coincide with the particular purpose, include, but are not limited to: Ensure the technical operation, responding to inquiries that are not related to the contract, ensure data security, ensure data availability, and rectification of errors and faults.

Your data will be processed pursuant to Art. 6, par. 1, lit. f of the GDPR. In the event we need to disclose data for these purposes, we will expressly notify you of this circumstance. In the absence of this information, we may not be able to process your inquiry.

We will delete your personal data if it is no longer required for the purposes we pursue and if no other statutory provisions apply. However, if the latter should be true, we will delete your data after all of statutory provisions cease to apply.

3.4. TELEPHONE CONTACT

In the event that we initially contact you by phone, we have generated your data from public sources.

Our interest in the initial telephone contact overrides the interest of the data subject, since we exclusively contact B2B customers via contact channels available from public sources and the contact refers to specific processes in connection with the business activity of the person concerned.

During this initial phone call, we will merely inquire whether this particular person is interested in establishing a contact with MHP and do not present our services comprehensively.

3.5. DATA PROCESSING FOR ADVERTISING PURPOSES

CRM and advertising measures are subject to certain legal requirements. Processing personal data for advertising purposes is permissible, it this use is compatible with the purpose for which this data had initially been collected. If data is exclusively collected for advertising purposes, we need your consent to the processing of your data for advertising purposes.

If you withdraw your consent to the use of your data for advertising purposes, the continued use of your data for these purposes is not permissible and it will be deleted without undue delay with effect for the future regarding these purposes.

3.6. CONSENT TO DATA PROCESSING

Processing of personal data is permissible with the prior written consent from the affected customer. If you should have granted your consent for certain purposes, the purposes are determined by the contents of the relevant statement of consent.

Your data will be processed pursuant to Art. 6, par. 1, lit. a of the GDPR.

You may withdraw your consent at any time, which, however, will not affect the legitimacy of data processing prior to the date of withdrawal.

We will delete your personal data without undue delay when you withdraw your consent or if we no longer need the data for the purposes pursued by us unless this act conflicts with statutory retention periods.

4. DATA DELETION AND STORAGE PERIOD

For data storage periods of personal data please refer to the relevant data processing chapter. In addition, the following general rule shall apply: we will store your personal data only as long as required for meeting the purposes or – if a consent was granted – as long as you do not withdraw your consent. In the event you withdraw your consent, we will delete your personal data without undue delay, unless their continued processing is permissible under the applicable statutory provisions. We will also delete your personal data if we are obligated to do so subject statutory requirements.

5. RECIPIENTS OF PERSONAL DATA

In-house recipients: Within MHP, only those employees will be allowed access that need access to personal data in accordance with the purposes set forth above in section 3.

Generally, your data will not be transmitted to third parties outside MHP, unless this is a mandatory statutory duty or if this data transmission is required for performing the contract, or if you have granted your express prior consent. External service providers and partner companies will only receive your data to the extent necessary for processing your inquiry. However, in these events, the scope of data transmitted will be restricted to the necessary minimum amount of data. To the extent our service providers have access to your personal data, we shall ensure that these will comply with the data protection law, rules, and regulations in the same manner. Please note the corresponding privacy policies of these service providers. The corresponding service provider is responsible for the contents of third-party services, provided, however, that we will monitor the services for their compliance with statutory provisions to the extent reasonable.

External recipients: Your data will be forwarded to service providers that perform services on our behalf and assist MHP in the provision of its services.

If your personal data is processed by commissioned service providers, these activities will be carried out within the scope of data processing pursuant to Art. 28 of the GDPR.

The service providers referred to above will only be granted access to such personal data that is needed for carrying out the corresponding tasks. These service providers are not allowed to pass on your personal data or to use it for any other purpose, in particular, for their own advertising or marketing purposes.

To the extent external service providers have access to your personal data, we have ensured by legal measures, privacy by default and by design, and through regular reviews and inspections that they will comply with the applicable data protection laws, rules, and regulations. Your personal data will not be transmitted to other companies for commercial purposes.

6. DATA PROCESSING IN THIRD COUNTRIES

In the event data is transmitted to third parties whose registered office, place of residence, or place of data processing is not within a member state of the European Union or another country that is a party to the Agreement on the European Economic Area, we will ensure prior to passing on your data that, except for the statutorily permitted exceptions, the recipient complies with a reasonable level of data protection (e.g., based on an adequacy decision of the European Commission, based on appropriate guarantees such as the self-certification of the recipient for the EU-U.S. Privacy Shield, or the agreement on the so-called EU Standard Contract Clauses of the European Union with the recipient) or that you have provided your sufficient consent.

7. AUTOMATED DECISION-MAKING

We neither use automated decision-making nor profiling.

8. DATA SECURITY

We use technical and organizational safeguards (privacy by default and by design) to protect your personal data against coincidental or willful manipulation, loss, destruction, or access by unauthorized parties. Our security measures will be continuously improved based on the state of the art.

9. RIGHTS OF THE DATA SUBJECT

If your personal data is processed, you are a “data subject” within the meaning of the GDPR and you are entitled to the following claims against the “controller”:

Right of access pursuant to Article 15 of the GDPR
You have the right to obtain from us confirmation as to whether or not personal data concerning you is being processed. If we have processed your personal data, you are entitled to further rights to access set forth in Article 15 of the GDPR.

Right to rectification
If data that we collected on you is inaccurate or incomplete, you may claim the rectification without undue delay pursuant to Article 16 of the GDPR.

Right to restriction of processing
Subject to Article 18 GDPR, you may also have the right to claim the restriction of processing of personal data concerning you. Where processing has been restricted, your personal data shall only be processed with your consent or for the assertion, exercise or defense of legal claims or for the protection of the rights of another natural or legal person, or for reasons of important public interest of the Union or of a Member State. We will notify you before the restriction is lifted.

Right to erasure
If one or more of the grounds listed in Article 17 par. 1 of the GDPR apply, you may claim the erasure of personal data concerning you without undue delay, unless there is an exception pursuant to Article 17, par. 3 of the GDPR.

Right to notification
If you have asserted the right to rectification, erasure of personal data, or restriction of processing, we are obligated pursuant to Article 19 of the GDPR to notify all recipients to whom personal data has been disclosed, unless this proves impossible or involves disproportionate effort. In addition, you have the right to be informed about who these recipients are. You may exercise your right to be informed of those recipients against the controller.

Right to data portability
Furthermore, pursuant to Article 20 of the GDPR, you have the right to receive the personal data concerning you in machine readable format and to transmit this data to another controller without hindrance, provided, however, that the conditions enumerated in Article 20, par. 1, lit. a of the GDPR exist, or to demand to have the personal data transmitted directly from us another controller, where technically feasible and if this does not adversely affect the rights and freedoms of others. This right shall not apply to processing of personal data necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.

Right to object
You have the right to object at any time to the processing of personal data concerning you by written notice to MHP which is based on Article 6, par 1, lit. f of the GDPR. We shall not longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms or if the processing serves the assertion, exercise or defense of legal claims.

Right to withdraw the consent under data protection law, rules, and regulations
You may withdraw your data protection consent at any time by notifying MHP. The withdrawal of consent shall not affect the lawfulness of processing based on this consent before its withdrawal.

Right to lodge complaints with the supervisory authority:
Furthermore, you have the right to lodge a complaint with the competent supervisory authority, if you consider that the processing of your personal data violates the applicable statutory provisions, rules, and regulations. In this case, you may contact the Data Protection Authority having competence at your place of residence or in your country or the Data Protection Authority having competence at our place of business.

How to contact us or to exercise your rights:
If you should have any questions on the processing of your personal data, your rights as a data subject, or any consent that may have been granted, you may contact us free of charge. If you wish to exercise any or all of your rights, please email us at info@mhp.com or write a letter to the address set forth in section 1 above.

10. THIRD PARTY OFFERS

Third party services that we refer to within the scope of our business relationship were and are designed and provided by third parties. We have no control over the design, contents, and functionality of these third party services. We expressly advise you that we do not assume any responsibility for any contents included in third-party offers. If applicable, please obtain information on these third party offers directly from the service providers.

11. LAST REVISED:

This Privacy Policy will be modified and/or amended when the internet or our web offering change. We will notify you of any updates on this page in due time. In order to stay informed on the current version of our Privacy Policy, please visit this web page at regular intervals.

This Privacy Policy shall apply as amended. Last revised: 5/24/2018