We are glad you visit our website and that you are interested in MHP Management- und IT-Beratung GmbH and in our services. Your privacy is an important concern to us. We handle the protection of your personal data and their strictly confidential processing with great care. Your personal data will be exclusively processed in compliance with the applicable provisions under data protection law.
1. DATA CONTROLLER AND DATA PROTECTION OFFICER; CONTACT
The Data Controller within the meaning of data protection laws, rules, and regulations is:
MHP Management- und IT-Beratung GmbH
Film- und Medienzentrum
phone: +49 (0)7141 7856-0
If you have any questions regarding data protection, please contact our data protection officer at dataprivacy(at)mhp.com.
2. SUBJECT MATTER
“Personal data” means any information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.
Other than described in the sections below, no personal data will be collected, processed, or used during the visit of our website. When you visit our website, our web servers will automatically capture general information. This includes the type of web browser, the operating system used, the domain name of the internet service provider, IP address of the computer used, the referring website, the pages of our website that you visit and the date and duration of your visit.
We cannot use this data to identify individual users. We will only analyze this information for statistical purposes and for improving the attractiveness, contents, and functionality of our website.
3. LEGAL BASIS OF DATA PROCESSING
In the event we obtain a consent from a data subject for the processing of personal data, Art. 6, par. 1, lit. a of the European General Data Protection Regulation (GDPR) forms the legal basis for processing your personal data.
If the processing of personal data is necessary for performing an agreement to which the data subject is a party this is governed by Art. 6, par. 1, lit. b of the General Data Protection Regulation (GDPR). This shall also apply to processing steps that are required to carry out tasks prior to the conclusion of an agreement.
If the processing of personal data is necessary for meeting a statutory obligation to which our company is bound, Art. 6, par. 1, lit. c of the General Data Protection Regulation (GDPR) forms the legal basis.
In the event processing is necessary in order to protect the vital interests of the data subject or of another natural person, Art. 6, par. 1, lit. d of the General Data Protection Regulation (GDPR) forms the legal basis for processing your personal data.
If data processing is necessary for the purposes of the legitimate interests pursued by our company or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, Art. 6 par. 1 lit. f of the General Data Protection Regulation (GDPR) forms the legal basis for processing your personal data.
The passing on of your personal data within the Porsche Group for the purpose of responding to and forwarding inquiries is also subject to these statutory provisions.
4. DELETION OF DATA AND STORAGE PERIOD
Personal data of the data subject will be deleted or blocked as soon as the purpose of storage ceases to apply. Data may be stored beyond this period, if provided by EU regulations, national law, or other rules and regulations adopted by the EU or national legislators by which the controller is bound. Data will also be blocked or deleted when a storage period set forth in any of the indicated rules and regulations expires unless the further storage of data is required for the conclusion of a contract or contract performance.
5. COLLECTION AND PROCESSING OF PERSONAL DATA
Personal data will only be collected if you provide it upon your own request, e.g., as a participant of a survey or when registering for personalized services. In these cases, you will be notified of the intended storage purpose and, if necessary, asked to grant your consent to data storage.
Personal data collected in connection with our website will only be used for filling orders or processing your inquiries unless you grant your consent to other forms of processing.
Any other form of processing requires your prior consent.
This use of data is restricted to the purposes of advertising and market and public opinion research and this data will be exclusively available to MHP.
You may withdraw your consent to a particular type of use at any time with effect to the future.
Your data will not be sold, rented, or made available to third parties in any manner other than those described herein. Data transmission of personal data to state and public authorities will only be carried out subject to mandatory national statutory provisions. Our employees, agencies, and dealers have been bound to the duty of strict confidentiality.
You may contact us by writing to our email address. Of course, we will use any personal data provided to us this way only for the purpose for which it was made available during this contact.
To the extent that our contact form contains fields that are not required for contacting you, these fields are marked as optional fields. This information helps us to gather further details regarding your inquiry and improves the handling of your concern.
We expressly draw your attention to the fact that you provide your information on a voluntary basis and that you grant your consent to us using it. In the event this should concern information on other communication channels (for instance, email account, phone number), you also provide your consent that we may contact you that way in order to respond to your inquiry.
In addition, at the time of sending the message the following data will be stored:
- IP address of use
- date and time of registration
Data processing is not permissible unless you have granted your consent.
Your personal data will not be passed on to third parties in connection herewith. This data will only be used for processing the conversation. Of course, you may withdraw this consent at any time with effect to the future by writing to firstname.lastname@example.org.
5.2. JOB APPLICATIONS
You may apply for a job with MHP online using our recruiting platform. Your online application is transmitted directly to the HR department via an encrypted connection and will be treated in strict confidence. Of course, we will use your information only for processing your application and will not pass it on to third parties.
If you have applied for a particular position and this position is has been filled or if we believe that you are similarly or even better suited for another position, we would like to pass on your application within the Porsche Group. In the course of the application process you may determine on the entry screen whether you agree with this forwarding or not.
Your personal data will be immediately deleted upon the completion of the application process or upon the expiration of a period of six (6) months unless you have granted your express consent to a longer storage period of your data.
Please note that we accept job applications only through our recruiting platform. If you should apply by email anyway, we expressly draw your attention to the fact that email attachments are not encrypted.
You may subscribe to our free newsletter on our website. When you register for our newsletter, the information provided on screen will be transmitted to us.
The processing of data obtained through a user’s registration for a newsletter is governed by Art. 6, par 1, lit. a of the GDPR, if the user has granted his/her consent.
If you acquire goods or services through our website and enter your email account for this purpose, we have the right to use this address for mailing a newsletter afterwards. In this case, the newsletter will only contain direct marketing contents for similar goods or services provided by us.
No data will be passed on to third parties in connection with data processing for newsletter mailings. This data will only be used for mailing the newsletter.
In addition, the following information will be collected at the time of registration:
- IP address of requesting compute
- date and time of registration
The user may unsubscribe from the newsletter at any time. Each newsletter will contain a link for this purpose.
By clicking this link, the user may withdraw his/her consent to storing the personal data that was collected during the registration process to take effect in the future.
Our website allows users to register by entering personal data. The user’s registration is required for providing certain contents and services on our website. We need your registration information in order to be able to send you your login data or event information.
Data processing is not permissible unless you have granted your consent.
You need to enter your data on screen and this information will be transmitted to and stored by us. Data will not be passed on to third parties. The following data will be collected during the registration process:
- Form of address
- First name
- Family name
- Zip code
In addition, at the time of registration the following data will be stored:
- IP address of use
- date and time of registration
Of course, you may withdraw this consent any time with effect to the future by writing to email@example.com.
5.5. TELEPHONE CONTACT
In the event that we initially contact you by phone, we have generated your data from public sources. Our interest in the initial telephone contact overrides the interest of the data subject, since we exclusively contact B2B customers via contact channels available from public sources and the contact refers to specific processes in connection with the business activity of the person concerned. During this initial phone call, we will merely inquire whether this particular person is interested in establishing a contact with MHP and do not comprehensively present our services.
5.6. PROVISION OF WEBSITE AND GENERATION OF LOGFILES
During each visit of our web pages, our system will automatically collect data and information from the retrieving computer system. The following information will be collected:
Information on the browser type and the version used
- User’s operating syste
- User’s internet service provider (ISP
- IP address of use
- date and time of acces
- Websites from which user’s system is referred to our websit
- Websites that the user’s system calls up through our website
This information will also be stored in the logfiles of our system. This information will not be stored together with other personal data of the user.
The temporary storing of data and logfiles is governed by Art. 6, par 1, lit. f of the GDPR.
The IP address needs to be temporarily stored by the system in order to allow the delivery of the website to the user’s computer. To this end, the IP address of the user needs to be stored during the entire session.
This information will be stored in logfiles in order to ensure the operability of the website. In addition, this data helps us to optimize our website and to ensure the security of our IT systems. This information will not be analyzed for marketing purposes. We have a legitimate interest in data processing for these purposes pursuant to Art. 6, par. 1, lit. f of the GDPR.
Data will be deleted as soon as it is no longer needed for attaining the purpose for which it was collected. With regard to the collection of data for the purpose of making the website available this is the case when the session concerned is over.
In the event data is stored in logfiles, data will be deleted no later than within seven (7) days. It is possible to store data for a longer period. In this case, the IP addresses of the users will be deleted or pseudonymized so that the retrieving software client may no longer be assigned to an individual.
6. WEBSITE OPTIMIZATION TOOLS
Our website uses both session cookies and permanent cookies. Session cookies are temporary cookies that are stored on the web browser of a user until the browser window is closed and, thus, the session cookies are deleted. Permanent cookies are used for return visits and will be stored in the user’s browser for a certain period (usually one (2) years or longer). These cookies are not deleted when the browser software is closed. This type of cookies will be used to reuse the user’s preferences once they return to our web page.
- Search terms entere
- Frequency of page view
- Use of website features
We use Matomo software to analyse and statistically evaluate the use of our website. The legal basis is legitimate interest pursuant to Art. 6 (1) (f) GDPR regarding the demand-oriented design and optimisation of the website.
We use Matomo without cookies. The information generated about website usage is transmitted to our servers and compiled in pseudonymous usage profiles. This enables us to analyse the use of the website and to ensure that our website is designed based on user needs. The information is not transferred to third parties. Under no circumstances will the IP address be linked to other data relating to the user. The IP addresses are anonymised so that an allocation is not possible (IP masking).
On our website, we use the cookie consent technology of Usercentrics GmbH, Sendlinger Straße 7, 80331 Munich, Germany (hereinafter „Usercentrics“), to obtain your consent to the storage of certain cookies on your terminal device and to document this in accordance with data protection law. Usercentrics uses a cookie to be able to assign the consent(s) granted to you as well as their revocation.
The processing of the data collected by Usercentrics is carried out on our behalf and on the basis of a data processing agreement.
For more information, please refer to the Usercentrics website: https://usercentrics.com/.
In CRM we use Salesforce. The Salesforce data is stored in the EU; only in the case of support, access from a third country cannot be ruled out. We have concluded a data protection agreement with the German Salesforce company that meets the requirements of Art. 44 et seq. GDPR.
6.5 Google Analytics
This website uses Google Analytics 4, a web analytics service provided by Google Ireland Ltd, Gordon House, Barrow Street, Dublin 4, Ireland ("Google"). The legal basis for this processing is your consent according to Art. 6 para. 1 lit. a DSGVO in conjunction with § 25 para. 1 TTDSG.
With your consent, "cookies" (text files) are stored on your end device to enable an analysis of the use of the website. A transmission of your IP address to Google servers in the USA takes place in anonymized form. For this purpose, we use a server-side tagging server (SSTS). On our behalf, Google uses the information to evaluate the use of the website, to compile reports on website activity and to provide us with other services related to the use of the website and the Internet. The user data will be deleted after 14 months at the latest.
You can revoke your consent at any time with effect for the future, and prevent the use of data by Google by downloading and activating the available browser plugin: http://tools.google.com/dlpage/gaoptout?hl=de or using the slider via the privacy settings of this website.
6.6 Facebook Pixel
We use Facebook-Pixel, a service of Meta Platforms Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. Legal basis for use is your consent on the basis of Art. 6 para. 1 lit. a GDPR. You can withdraw your consent at any time with effect for the future. To change permission, click „Deactivate Facebook Pixel”.
The Facebook Pixel allows us to display relevant advertising on Facebook following your visit to our website, if you are a Facebook user; for example, if you are interested in certain products we offer. Even the way back, for instance when clicking on one of our ads on Facebook and accessing our website, can be measured with Facebook Pixel. All in all, we would like to monitor the promotional impact on Facebook and thus optimise the use of advertising means. No link to your account with us or a link to other services shall be created. For more information relating to privacy information, please check back at https://www.facebook.com/policy. As a Facebook user, you can also manage which advertising shall be shown to you on Facebook.
When using the pixel, it cannot be ruled out that data will be transferred to the USA. A data transfer to the USA shall only be carried out if the requirements of Articles 44 et seqq. GDPR are fulfilled.
6.7 LinkedIn Insight Tag
We use LinkedIn Insights Tag on our website, a service of LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland. The purpose of its use is to analyze the success of our advertising on LinkedIn. Through the LinkedIn Insight Tag, data about visitors to the website is collected: URL, referrer URL, IP address, device and browser properties (user agent), and timestamp. IP addresses are shortened or (if used to reach members across devices) hashed. Members' direct identifiers are removed within seven days to pseudonymize the data. This remaining pseudonymized data is then deleted within 180 days. For us, the processing is not attributable to your person (IP masking). During use, a transmission of data to the LinkedIn Corporation in the USA is not excluded. A data transfer to the USA only takes place if the requirements of Artt. 44 ff. GDPR are fulfilled.
The legal basis for the use is your consent according to Art. 6 para. 1 lit. a GDPR. You can change your consent at any time with effect for the future via the settings of our consent tool or object to the processing via this link:
Furthermore, if you have a LinkedIn profile, you can set the data collection centrally for all websites with LinkedIn technology for your profile in the Linkedin settings: https://www.linkedin.com/psettings/enhanced-advertising
Information on data protection at LinkedIn can be found here: https://www.linkedin.com/legal/privacy-policy.
7. DATA TRANSMISSION
Data transmission to other group companies
Generally, your data will not be transmitted to third parties outside MHP, unless this is a mandatory statutory duty or if this data transmission is required for performing the contract or if you have granted your express prior consent. External service providers and partner companies will only receive your data to the extent necessary to process your inquiry. However, in these events, the scope of data transmitted will be restricted to the necessary minimum amount of data. To the extent that our service providers have access to your personal data, we shall ensure that these will comply with the data protection law, rules, and regulations in the same manner. Please note the corresponding privacy policies of these service providers. The corresponding service provider is responsible for the contents of third-party services, provided, however, that we will monitor the services for their compliance with statutory provisions to the extent reasonable.
Data transmission to external service providers (processors)
Your data will be forwarded to service providers that perform services on our behalf and assist MHP in the provision of its services.
If your personal data is processed by commissioned service providers, these activities will be carried out within the scope of data processing pursuant to Art. 28 of the GDPR. The service providers referred to above will only be granted access to such personal data that is needed for performing the corresponding tasks. These service providers are not allowed to pass on your personal data or to use it for any other purpose, in particular, for their own advertising or marketing purposes.
To the extent that external service providers have access to your personal data, we have ensured by legal measures, privacy by default and by design, and through regular reviews and inspections that they will comply with the applicable data protection laws, rules, and regulations.
Your personal data will not be transmitted to other companies for commercial purposes.
Integration of YouTube
8. DATA SECURITY
We use technical and organizational safeguards (privacy by default and by design) to protect your personal data against coincidental or willful manipulation, loss, destruction or access by unauthorized parties. Our security measures will be continuously improved based on the state of the art.
9. RIGHTS OF THE DATA SUBJECT
If your personal data is processed, you are a “data subject” within the meaning of the GDPR and you are entitled to the following claims against the “controller”:
Right of access pursuant to Article 15 of the GDPR
You have the right to obtain from us confirmation as to whether or not personal data concerning you is being processed. If we have processed your personal data, you are entitled to further rights to access set forth in Article 15 of the GDPR.
Right to rectification
If data that we collected on you is inaccurate or incomplete, you may claim the rectification without undue delay pursuant to Article 16 of the GDPR.
Right to restriction of processing
Subject to Article 18 GDPR, you may also have the right to claim the restriction of processing of personal data concerning you. Where processing has been restricted, your personal data shall only be processed with your consent or for the assertion, exercise or defense of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the Union or of a Member State. We will notify you before the restriction is lifted.
Right to erasure
If one or more of the grounds listed in Article 17 par. 1 of the GDPR apply, you may claim the erasure of personal data concerning you without undue delay, unless there is an exception pursuant to Article 17, par. 3 of the GDPR.
Right to notification
If you have asserted the right to rectification, erasure of personal data, or restriction of processing, we are obligated pursuant to Article 19 of the GDPR to notify all recipients to whom personal data has been disclosed, unless this proves impossible or involves disproportionate effort. In addition, you have the right to be informed about who these recipients are. You may exercise your right to be informed of those recipients against the controller.
Right to data portability
Furthermore, pursuant to Article 20 of the GDPR, you have the right to receive the personal data concerning you in machine readable format and to transmit this data to another controller without hindrance, provided, however, that the conditions enumerated in Article 20, par. 1, lit. a of the GDPR exist or to demand to have the personal data transmitted directly from us another controller, where technically feasible and if this does not adversely affect the rights and freedoms of others. This right shall not apply to processing of personal data necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.
Right to object
You have the right to object at any time to processing of personal data concerning you by written notice to MHP which is based on Article 6, par 1, lit. f of the GDPR. We shall not longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms or if the processing serves the assertion, exercise or defense of legal claims.
Right to withdraw the consent under data protection law, rules, and regulations
You may withdraw your data protection consent at any time by notifying MHP. The withdrawal of your consent shall not affect the lawfulness of processing based on this consent prior to its withdrawal.
Right to lodge complaints with the supervisory authority:
Furthermore, you have the right to lodge a complaint with the competent supervisory authority, if you consider that the processing of your personal data violates the applicable statutory provisions, rules, and regulations. In this case, you may contact the Data Protection Authority having competence at your place of residence or in your country or the Data Protection Authority having competence at our place of business.
How to contact us or to exercise your rights:
Furthermore, if you should have any questions on the processing of your personal data, your rights as a data subject, or any consent that may have been granted, you may contact us free of charge. If you wish to exercise any or all of your rights, please email us at firstname.lastname@example.org or write a letter to the address set forth in section 1 above.
10. MODIFICATONS AND AMENDMENTS