Privacy Policy
of HAGEN+TRIEBSCH GmbH
Version 2.0 · Effective: 1 September 2026 · replaces the August 2019 version
1. Controller and contact
The controller responsible for the processing of personal data within the meaning of Art. 4 no. 7 of Regulation (EU) 2016/679 (General Data Protection Regulation, "GDPR") is:
HAGEN+TRIEBSCH GmbH
Schloßstraße 8d
22041 Hamburg
Germany
Phone: +49 40 67587799-0
Email: info@hagen-triebsch.de
Web: www.hagen-triebsch.de
Represented by the managing directors Timo Triebsch and Kevin Greßmann. Register court: Amtsgericht Hamburg, HRB 119629. VAT ID: DE278588030.
2. Data Protection Officer
We have voluntarily appointed a Data Protection Officer. You can reach them at:
Data Protection Officer of HAGEN+TRIEBSCH GmbH
Schloßstraße 8d, 22041 Hamburg
Email: datenschutz@hagen-triebsch.de
Any data protection concern you raise with the Data Protection Officer will be handled confidentially.
3. Principles of our processing
We process personal data solely on a lawful basis and only to the extent necessary for the stated purposes. You can generally use our website without providing personal data; certain functions, such as contacting us, require you to supply specific data.
Personal data means any information relating to an identified or identifiable natural person. Processing means any operation performed on such data, in particular collection, storage, use, transmission and erasure.
4. Overview of processing activities
| Purpose | Legal basis | Retention period |
|---|---|---|
| Provision of the website | Art. 6(1)(f) GDPR | 7 days (server log files) |
| Defence against attacks | Art. 6(1)(f) GDPR | up to 90 days in case of suspicious activity |
| Contact requests and quotations | Art. 6(1)(b) and (f) GDPR | up to 24 months after last contact |
| Contract performance | Art. 6(1)(b) GDPR | duration of the contract, then statutory periods |
| Service portal and support | Art. 6(1)(b) GDPR | 4 years after case closure |
| Accounting and tax | Art. 6(1)(c) GDPR | 7, 9 or 11 years (statutory period of 6, 8 or 10 years plus a buffer for the erasure cycle) |
| Applications | Art. 6(1)(b) and (f) GDPR, § 26 BDSG | 6 months after receipt of the rejection |
| Information security | Art. 6(1)(c) and (f) GDPR | depending on the log type, no longer than 12 months |
This overview is a summary. The details are set out in the sections that follow.
5. Provision of the website and server log files
Each time our website is accessed, the web server automatically records the following information and stores it in log files:
- the requested page or file,
- date and time of access,
- volume of data transferred and status of the request,
- type and version of the browser used,
- operating system used,
- the previously visited page (referrer),
- the IP address of the accessing system.
Purpose. The processing is necessary to deliver the website technically, ensure its stability and security, detect malfunctions and defend against attacks.
Legal basis. Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure and trouble-free operation of our online services.
Retention period. Log files are deleted after seven days. If an entry indicates an attack or abusive use, we retain the affected entries for no longer than 90 days in order to investigate the incident and pursue legal claims where necessary.
Recipients. The website is operated by a service provider acting on our behalf as a processor pursuant to Art. 28 GDPR. Processing takes place within the European Union.
6. Cookies and comparable technologies
Cookies are small text files stored on your device. Comparable technologies include browser local storage and scripts that retrieve information from your device.
Strictly necessary cookies. We use cookies that are strictly necessary for the operation of the website, for example to store your language preference or to secure form submissions. Access to your device in this case is permitted without consent under § 25(2)(2) of the German Telecommunications and Digital Services Data Protection Act (TDDDG). The legal basis for the subsequent processing of personal data is Art. 6(1)(f) GDPR.
Consent-based technologies. Cookies and comparable technologies that are not strictly necessary — in particular for reach measurement or the integration of third-party content — are only used with your prior consent under § 25(1) TDDDG and Art. 6(1)(a) GDPR. You give consent via the consent dialog that appears the first time you visit our website. You may withdraw your consent at any time via the privacy settings on our website; the lawfulness of processing carried out prior to withdrawal remains unaffected.
Browser settings. Independently of the above, you can restrict or prevent the setting of cookies in your browser and delete cookies that have already been set. If you disable strictly necessary cookies, some functions of our website may not be usable.
7. Contacting us
7.1 Contact form
You can send us an enquiry via the form on our website. We process the data you provide: subject, name, company, email address, phone number and the content of your message. We additionally store the time of submission and the IP address from which the submission was made.
Purpose. Handling your enquiry, preparing a quotation, and evidence and defence against abusive use of the form.
Legal basis. Art. 6(1)(b) GDPR where the enquiry is aimed at the conclusion or performance of a contract, otherwise Art. 6(1)(f) GDPR based on our legitimate interest in answering enquiries and in the security of our systems.
Mandatory fields. The fields marked as required must be filled in. Without this information we cannot handle your enquiry. Any further information is voluntary.
Retention period. We delete the data as soon as your enquiry has been fully handled and no statutory retention obligations prevent deletion, at the latest 24 months after the last contact. If the enquiry leads to a contract, Section 9 applies.
7.2 Email and telephone
If you contact us by email or telephone, we process the data transmitted in the course of that contact in order to handle your request. The legal basis and retention period correspond to Section 7.1. Please note that unencrypted emails can be read in transit by third parties. For the encrypted transmission of sensitive information we will provide a suitable channel on request.
Our email communication is handled via Microsoft 365. The provider is Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland, acting on our behalf as a processor.
8. Service portal and support
For reporting and handling incidents, enquiries and change requests we operate a service portal based on Jira Service Management. The provider is Atlassian Pty Ltd, 350 Bourke Street, Level 6, Melbourne VIC 3000, Australia, represented in Europe by Atlassian B.V., Amsterdam, Netherlands.
Data processed: name, business contact details, assignment to the client, content and history of the ticket, technical details of the affected system, attachments and log data about accesses and processing steps.
Purpose: delivery of the agreed support and operations services, evidence of service delivery and compliance with the agreed service levels.
Legal basis: Art. 6(1)(b) GDPR in relation to our clients and Art. 6(1)(f) GDPR with regard to logging. Where we operate the service portal on behalf of a client for that client's staff, we process the data as a processor pursuant to Art. 28 GDPR; in that case the client is the controller and you should address your rights to them.
Retention period: Cases are deleted four years after closure unless a longer retention has been contractually agreed or is legally required. This period corresponds to the standard limitation period of three years under § 195 of the German Civil Code (BGB) plus a buffer for the execution of the erasure runs.
Third-country transfers: Processing outside the European Union cannot be excluded. It takes place on the basis of the Standard Contractual Clauses of the European Commission pursuant to Art. 46(2)(c) GDPR in conjunction with supplementary safeguards. Details are available on request.
9. Customer, prospect and business partner data
Data processed: company name and address, names and roles of contact persons, business contact details, contract and performance data, billing and payment data, correspondence.
Purposes: initiation, conclusion and performance of contracts, invoicing, receivables management, compliance with commercial and tax obligations, evidence of service delivery and information about our own services within an existing business relationship.
Legal bases: Art. 6(1)(b) GDPR for contract performance, Art. 6(1)(c) GDPR for statutory retention and record-keeping obligations, Art. 6(1)(f) GDPR for maintaining the business relationship and asserting our own legal claims.
Retention period: After the business relationship ends we delete the data as soon as it is no longer needed for the stated purposes. Documents subject to commercial or tax retention obligations are retained for six, eight or ten years under § 147 of the German Fiscal Code (AO) and § 257 of the German Commercial Code (HGB), calculated from the end of the calendar year in which the document was created. Because our erasure runs take place annually, actual retention can extend by up to twelve months. Data required for asserting, exercising or defending legal claims is retained until the relevant limitation periods have expired.
10. Applications
Data processed: cover letter, CV, certificates and other documents you submit, contact details, information on qualifications and professional experience, and notes from selection interviews.
Purposes and legal bases: conducting the application procedure and deciding on the establishment of an employment relationship, based on Art. 6(1)(b) GDPR and § 26(1) sentence 1 BDSG. Where you voluntarily provide us with additional information, the legal basis is your consent under Art. 6(1)(a) GDPR. We base the defence against claims under the General Equal Treatment Act (AGG) on Art. 6(1)(f) GDPR.
Submission: Please send applications to bewerbung@hagen-triebsch.de. Access is restricted to the persons involved in the selection decision and to management.
Retention period: If no employment relationship is entered into, we delete the application documents six months after receipt of the rejection. This period takes into account the two-month period for asserting claims under § 15(4) AGG and the subsequent three-month limitation period for filing a lawsuit under § 61b(1) of the German Labour Court Act. If you consent to a longer inclusion in our applicant pool, we retain your documents for the period you specify, but no longer than 24 months. If you are hired, we transfer the documents to your personnel file.
Voluntary nature: Submitting your application documents is voluntary. However, without the information required for the assessment we cannot consider your application. We ask you not to send us any information about special categories of personal data within the meaning of Art. 9 GDPR, in particular relating to health, religion or trade union membership, unless it is necessary for the application.
11. Employee data
We process our employees' data for the establishment, performance and termination of the employment relationship on the basis of § 26 BDSG in conjunction with Art. 6(1)(b) GDPR, for the fulfilment of statutory obligations under Art. 6(1)(c) GDPR and, where applicable, on the basis of works agreements or your consent. We inform our employees about the details separately.
12. Information security and logging
To protect our systems and our clients' data, we log access to our IT systems, in particular sign-ins, administrative activities and security-relevant events. The legal basis is Art. 6(1)(f) GDPR and, to the extent statutory security requirements apply, Art. 6(1)(c) GDPR. No behaviour or performance monitoring takes place. Log data is deleted after no more than twelve months, depending on the log type.
13. Recipients and processors
Within our company, only those departments that need your data to fulfil the stated purposes are granted access to it.
We use carefully selected service providers who act on our behalf as processors pursuant to Art. 28 GDPR. We have concluded a data processing agreement with each of these providers and reviewed their technical and organisational measures before engaging them. These include, in particular, providers in the following areas:
- provision and operation of our website,
- provision of communication and collaboration services (Microsoft 365),
- provision of cloud infrastructure (Microsoft Azure),
- provision of the service portal (Atlassian),
- management of data in Microsoft 365 (AvePoint),
- data backup and restore,
- tax advisory and payroll,
- document shredding and data carrier disposal.
Transfers to further recipients only take place where there is a legal obligation — in particular to tax authorities, social security institutions, law enforcement authorities and supervisory authorities — where the transfer is necessary for the performance of a contract, for example to credit institutions and shipping service providers, or where you have consented.
We do not sell your data and do not pass it on to third parties for advertising purposes.
14. Transfers to third countries
We process personal data primarily within the European Union and the European Economic Area.
Where individual service providers process data in a third country or can access data from a third country, we do so on one of the following bases:
- an adequacy decision of the European Commission pursuant to Art. 45 GDPR, in particular for the United States of America based on the EU-US Data Privacy Framework for certified companies,
- the Standard Contractual Clauses of the European Commission pursuant to Art. 46(2)(c) GDPR, supplemented by additional technical and organisational safeguards, in particular encryption and restriction of access rights,
- an explicit consent pursuant to Art. 49(1)(a) GDPR.
A copy of the relevant safeguards is available on request.
15. Automated decision-making and profiling
Automated decision-making in individual cases, including profiling within the meaning of Art. 22 GDPR, does not take place.
16. Your rights
You have the following rights with respect to us:
- Access (Art. 15 GDPR). You can request information about whether and which of your personal data we process, and receive a copy of that data.
- Rectification (Art. 16 GDPR). You can request the correction of inaccurate data and the completion of incomplete data.
- Erasure (Art. 17 GDPR). You can request the deletion of your data where the conditions are met and no statutory retention obligation stands in the way.
- Restriction of processing (Art. 18 GDPR). You can request that we restrict the processing of your data.
- Data portability (Art. 20 GDPR). You can request that we provide the data you have supplied in a structured, commonly used and machine-readable format, where processing is based on consent or a contract and is carried out by automated means.
- Withdrawal of consent (Art. 7(3) GDPR). You can withdraw consent you have given at any time with effect for the future.
- Complaint (Art. 77 GDPR). You can lodge a complaint with a data protection supervisory authority.
To exercise your rights, please use the contact details given in Section 1 or Section 2. We will respond to your request without undue delay and at the latest within one month of receipt. We may extend this period by up to two further months if this is necessary due to the complexity or number of requests; in that case we will inform you of the extension and the reasons for it. In order to avoid disclosing information to unauthorised persons, we may request additional information to confirm your identity.
17. Right to object
Under Art. 21 GDPR you have the right, on grounds relating to your particular situation, to object at any time to the processing of your personal data carried out on the basis of Art. 6(1)(e) or (f) GDPR. We will then no longer process the data concerned unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.
If your data is processed for direct marketing purposes, you have the right to object at any time without giving reasons. Following such an objection we will no longer process your data for direct marketing purposes.
An objection is not subject to any particular form and can be sent to the contact details given in Section 1 or Section 2.
18. Competent supervisory authority
The Hamburg Commissioner for Data Protection and Freedom of Information
Ludwig-Erhard-Straße 22, 7th floor
20459 Hamburg, Germany
Phone: +49 40 428546-0
Email: mailbox@datenschutz.hamburg.de
Independently of this, you may contact the supervisory authority of your place of residence or workplace.
19. Requirement to provide data
The provision of personal data is required by law or by contract only to the extent stated in the preceding sections. Otherwise, providing data is voluntary. Without the data required to perform a contract we are unable to conclude or perform that contract.
20. Data security
We implement technical and organisational measures in accordance with Art. 32 GDPR to protect your data against loss, destruction, manipulation and unauthorised access. Our measures follow the ISO/IEC 27001 standard and the VdS 10000 guideline and are reviewed regularly and adapted to the state of the art. Data transmission via our website is encrypted using the Transport Layer Security protocol.
21. Status and changes to this privacy policy
This privacy policy is dated 1 September 2026 and replaces the version from August 2019. We will update it if our processing activities, the services we use or the applicable legal framework change. The current version is always available on our website.