Skip to main content

Processing of (personal) data by the entity in charge of the online application process

Privacy Policy


We are very pleased about your interest in our company. Data protection is of particularly high importance to the management of APC AG. The processing of your data is always carried out in accordance with the EU General Data Protection Regulation (GDPR) and in compliance with the country-specific data protection regulations applicable to APC AG. By means of this privacy policy, we would like to inform you comprehensively about the processing of your personal data by APC AG and the rights to which you are entitled.

Personal data refers to any information that makes it possible to identify a natural person. This includes, in particular, your name, date of birth, address, telephone number, email address, but also your IP address. Anonymous data exists when no personal reference to the user can be established.

As the controller, APC AG has implemented numerous technical and organizational measures to ensure the most complete protection possible for personal data processed via this website.

1. Controller

APC AG Ostendstraße 132

90482 Nuremberg, Germany

Tel.: +49 (0)911 504 999 0

Email: apc@apc-ag.de

Website: www.apc-ag.de

2. Contact Details of the Data Protection Officer

Email: apc-datenschutz@atarax.de

Any data subject may contact our Data Protection Officer directly at any time with any questions or suggestions regarding data protection.

3. Your Rights as a Data Subject

First, we would like to inform you about your rights as a data subject. These rights are standardized in Art. 15 - 22 GDPR. This includes:

  • The right of access (Art. 15 GDPR)

  • The right to erasure (Art. 17 GDPR)

  • The right to rectification (Art. 16 GDPR)

  • The right to data portability (Art. 20 GDPR)

  • The right to restriction of data processing (Art. 18 GDPR)

  • The right to object to data processing (Art. 21 GDPR)

To exercise these rights, please contact: apc-datenschutz@atarax.de. The same applies if you have questions about data processing in our company or wish to withdraw consent you have previously granted. You also have the right to lodge a complaint with a data protection supervisory authority.

4. Rights to Object

In connection with the right to object, please note the following:

If we process your personal data for the purpose of direct advertising, you have the right to object to this data processing at any time without giving reasons. If you object to processing for direct marketing purposes, we will no longer process your personal data for these purposes. The objection is free of charge and can be made informally, preferably to: apc-datenschutz@atarax.de.

In the event that we process your data to protect legitimate interests, you may object to this processing at any time for reasons arising from your particular situation. We will then no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights, and freedoms, or the processing serves the establishment, exercise, or defense of legal claims.

5. Purposes and Legal Bases of Processing

The processing of your personal data complies with the provisions of the GDPR and all other applicable data protection regulations. Legal bases for data processing arise in particular from Art. 6 GDPR.

We use your data for business initiation, to fulfill contractual and legal obligations, to offer products and services, and to strengthen the customer relationship. Your consent to data processing may also constitute a legal permission under data protection law. Before granting consent, we will inform you about the purpose of the data processing and your right of withdrawal.

If the processing of personal data is based on Art. 6(1)(f) GDPR, our legitimate interest is the conduct of our business activities for the benefit of the well-being of all our employees and our shareholders.

6. Disclosure to Third Parties

We will only pass on your data to third parties within the framework of legal provisions or with corresponding consent. Otherwise, no disclosure to third parties will take place unless we are obliged to do so by mandatory legal regulations (e.g., disclosure to supervisory authorities or law enforcement agencies).

7. Recipients of Data / Categories of Recipients

Within our company, we ensure that only those persons receive your data who need it to fulfill contractual and legal obligations. In certain cases, service providers support our departments (e.g., IT shipping). The necessary data protection contracts have been concluded with all service providers.

8. Transfer to Third Countries

Data transfer to third countries (outside the EU/EEA) only takes place if necessary for the execution of the contractual relationship, if required by law, or if you have given us your consent. We do not transfer your personal data to any service provider or group company outside the EEA.

9. Duration of Storage

We store your data as long as it is required for the respective processing purpose. Please note that numerous retention periods require continued storage (e.g., commercial or tax law retention obligations). If no further retention obligations exist, the data is routinely deleted once the purpose has been achieved.

10. Secure Transmission of Your Data

To best protect your data, we use technical and organizational security measures. Data exchange to and from our website is encrypted via HTTPS using current encryption protocols. We also offer content encryption for contact forms and applications.

11. Obligation to Provide Data

Various personal data are necessary for the establishment, execution, and termination of the contractual relationship. Without providing this data, processing your request or executing the contract is not possible.

12. Categories, Sources, and Origin of Data

The data we process is determined by the respective context (e.g., contact form or registration).

12.1 Website Visits

When visiting our website, we may process browser types, operating systems, referrer URLs, date/time of access, and IP addresses. This is based on our legitimate interest (Art. 6(1)(f) GDPR) in technical site operation.

12.2 Login Areas

For portals like APC DocuWeb, we collect login data (username/email and password). Passwords are stored in encrypted form.

12.3 Contact Form

Data provided via the contact form (name, company, contact details, message, IP address) is processed to answer your inquiries.

12.4 Webinars

For webinar registration, we process: Name, salutation, zip code/city, and email address.

13. Notice for Customers, Suppliers, and Interested Parties

We process your contact, professional, and payment data for pre-contractual measures, contract fulfillment (Art. 6(1)(b) GDPR), or legal obligations (Art. 6(1)(c) GDPR). We also use data to maintain customer relationships (Art. 6(1)(f) GDPR).

14. Notice for Applicants

Application data is processed solely for the recruitment process (Art. 6(1)(b) GDPR, § 26 BDSG). Storage usually ends six months after a decision, or 12 months if you consent to our talent pool.

15. Automated Decision-Making

We do not use automated decision-making.

16. Cookies

Our website uses cookies. Technically necessary cookies are used based on Art. 6(1)(f) GDPR. Other cookies are only used with your consent, which can be withdrawn via our consent banner at any time.

17. Google Analytics

Based on your consent (Art. 6(1)(a) GDPR), we use Google Analytics with IP anonymization. Data is transferred to Google servers in the USA. You can prevent collection via a browser plugin or our consent banner.

18. Google Tag Manager

We use Google Tag Manager (Art. 6(1)(f) GDPR) to manage website tags. The tool itself does not collect personal data.

19. Microsoft Teams

For webinars, we use MS Teams. User, connection, and metadata are processed. Video/audio data is only processed if you enable your camera/microphone. MS Teams processes data in the USA; Microsoft is contractually obligated to ensure EU data protection standards. For more info: https://privacy.microsoft.com/en-us/privacystatement.

20. Social Media Links

Our website links to Xing. Clicking the link establishes a connection to Xing’s servers. If you are logged in, Xing can assign this visit to your account. Their servers are located in the USA and other non-EU countries.

21. Social Media Presence

We maintain a corporate presence on Xing (New Work SE). Processing is based on our legitimate interest in communication (Art. 6(1)(f) GDPR). For opt-outs and details, see: https://privacy.xing.com/en/privacy-policy.

22. Podcasts

Our podcasts are hosted by ART19, LLC (USA). When you listen to a podcast, data is processed in the USA. By using this service, you declare your consent (Art. 49(1)(a) GDPR).Listener Analysis: If you consent, we process activity data (titles heard, duration, IP, device type) via ART 19 cookies. More info: https://art19.com/privacy.

23. Copyright Notice

When publishing content on our social media presence, you may be transferring usage rights to the network. Ensure you have the necessary rights to avoid legal consequences.

24. External Links

We are not responsible for the content of linked external websites. These were checked for legal violations at the time of linking. If violations become known, the links will be removed immediately.

Processing of (personal) data by the operator of the recruitment website

General information

This recruitment website is operated by Personio SE & Co. KG, which offers a human resource and candidate management software solution (https://www.personio.com/legal-notice/). Data transmitted as part of your application will be transferred using TLS encryption and stored in a database. The sole controller of this data within the meaning of article 24 of the GDPR is the enterprise carrying out this online application process. Personio’s role is limited to operating the software and this recruitment website and, in this context, being a processor under article 28 of the GDPR. In this case, the processing by Personio is based on an agreement for the processing of orders between the controller and Personio. In addition, Personio SE & Co. KG processes further data, some of which may be personal data, to provide its services, in particular for operating this recruitment website. We will refer to this in more detail below.

The controller

The controller under data protection law is:
Personio SE & Co. KG
Seidlstraße 3
80335 München
Tel.: +49 (89) 1250 1004
Entry in the commercial register
Commercial register entry number: HRA 115934
Registration Court: Amtsgericht München
Data Protection Officer contact: privacy@personio.com

Access logs (“server logs”)

Each access to this recruitment website automatically causes general protocol data, so-called server logs, to be collected. As a rule, this data is a pseudonym and thus does not allow for inferences about the identity of an individual. Without this data, it would, in some cases, be technically impossible to deliver or display the contents of the software. In addition, processing this data is absolutely necessary under security aspects, in particular for access, input, transfer, and storage control. Furthermore, this anonymous information can be used for statistical purposes and for optimizing services and technology. In addition, the log files can be checked and analyzed retrospectively when unlawful use of the software is suspected. The legal basis for this is §25 subsection 2 Sentence 2 TDDDG. Generally, data such as the domain name of the website, the web browser and web-browser version, the operating system, the IP address, as well as the timestamp of the access to the software is collected. The scope of this log process does not exceed the common log scope of any other site on the web. These access logs are stored for a period of up to 7 days. There is no right to object to this.

Error logs

So-called error logs are generated for the purpose of identifying and fixing bugs. This is absolutely necessary to ensure we can react as quickly as possible to possible problems with displaying and implementing content (legitimate interest). As a rule, this data is a pseudonym and thus does not allow for inferences about the identity of an individual. The legal basis for this is §25 subsection 2 Sentence 2 TDDDG. When an error message occurs, general data such as the domain name of the website, the web browser and web-browser version, the operating system, the IP address, as well as the timestamp upon occurrence of the respective error message and/or specification is collected. These error logs are stored for a period of up to 7 days. There is no right to object to this.

Use of cookies

So-called cookies are used on parts of this recruitment website. They are small text files which are stored on the device with which you access this recruitment website. As a general rule, cookies serve the purpose of ensuring secure access to a website (“absolutely necessary”), implementing certain functionalities such as standard-language settings (“functional”), improving the user experience or the performance of the website (“performance”), or placing targeted advertisements (“marketing”). On this recruitment website, we generally use only cookies that are absolutely necessary, functional or performance-related, in particular for implementing certain default settings such as language, for identifying the job advertising channel, or for analyzing the performance of a job advert via which a user accessed this recruitment website. The use of cookies is absolutely necessary for providing our services and thus for the performance of the contract (article 6 (1) b) of the GDPR). Period of storage: up to 1 month or until the end of the browser session Right to object: You can determine via your browser settings whether you allow or object to the use of cookies. Please note that deactivating cookies may result in limited or completely blocked functionalities of this recruitment website.

Rights of data subjects

If Personio SE & Co. KG as the controller processes personal data, you as the data subject have certain rights under Chapter III of the EU General Data Protection Regulation (GDPR), depending on the legal basis and the purpose of the processing, in particular the right of access (article 15 of the GDPR) and the rights to rectification (article 16 of the GDPR), erasure (article 17 of the GDPR), restriction of processing (article 18 of the GDPR), and data portability (article 20 of the GDPR), as well as the right to object (article 21 of the GDPR). If the personal data is processed with your consent, you have the right to withdraw this consent under article 7 III of the GDPR. To assert your rights as a data subject in relation to the data processed for the purpose of operating this recruitment website, please refer to Personio SE & Co. KG’s Data Protection Officer (see item B).

Concluding provisions

Personio reserves the right to adjust this data privacy statement at any point in time to ensure that it is in line with the current legal requirements at all times, or in order to accommodate changes in the services offered, for example when new services are introduced. In this case, the new data privacy statement applies to any later visit of this recruitment website or any later job application.