Data protection
1. Introduction
This website is operated by: AnCa Human Resource GmbH.
It is very important to us to handle our website visitors' data confidentially and to protect it in the best possible way. For this reason, we make every effort to comply with the requirements of the GDPR.
Below we explain how we process your data on our website. We use language that is as clear and transparent as possible so that you really understand what happens to your data.
2. General information
2.1 Processing of personal data and other terms
Data protection applies to the processing of personal data. Personal data means all data with which you can be personally identified. This is, for example, the IP address of the device (PC, laptop, smartphone, etc.) you are currently sitting in front of. Such data is processed when 'something happens to it'. Here, for example, the IP is transmitted from the browser to our provider and automatically stored there. This is then a processing (according to Art. 4 No. 2 GDPR) of personal data (according to Art. 4 No. 1 GDPR).
These and other legal definitions can be found in Art. 4 GDPR.
2.2 Applicable regulations/laws - GDPR, BDSG and TDDDG
The scope of data protection is regulated by law. In this case, these are the GDPR (General Data Protection Regulation) as a European regulation and the BDSG (Federal Data Protection Act) as a national law.
In addition, the TDDDG supplements the provisions of the GDPR as far as the use of cookies is concerned.
2.3 The person responsible
The controller within the meaning of the GDPR is responsible for data processing on this website. This is the natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data.
You can reach the person responsible at:
AnCa Human Resource GmbH
Hans-Diemer-Weg
89420 Höchstädt
2.4 How data is generally processed on this website
As we have already established, there is data (e.g. IP address) that is collected automatically. This data is mainly required for the technical provision of the website. If we also use personal data or collect other data, we will inform you of this or ask for your consent.
You consciously provide us with other personal data.
You will find detailed information on this below.
2.5 Your rights
The GDPR provides you with comprehensive rights. These include, for example, free information about the origin, recipient and purpose of your stored personal data. You can also request the rectification, blocking or erasure of this data or lodge a complaint with the competent data protection supervisory authority. You can revoke your consent at any time.
You can find out what these rights look like in detail and how to exercise them in the last section of this Privacy Policy.
2.6 Data protection - Our view
Data protection is more than just a chore for us! Personal data has great value and careful handling of this data should be a matter of course in our digitalized world. As a website visitor, you should also be able to decide for yourself what "happens" to your data, when and by whom. That is why we are committed to complying with all legal regulations, only collect the data that is necessary for us and, of course, treat it confidentially.
2.7 Forwarding and deletion
The transfer and deletion of data are also important and sensitive issues. We would therefore like to briefly inform you in advance about our general approach to this.
Data will only be passed on on the basis of a legal basis and only if this is unavoidable. This may be the case in particular if it is a so-called Data Processor and a Data Processing Agreement has been concluded in accordance with Art. 28 GDPR.
We delete your data when the purpose and legal basis for processing no longer apply and the deletion does not conflict with any other legal obligations. Art. 17 GDPR also provides a 'good' overview of this.
For further information, please refer to this Privacy Policy and contact the person responsible if you have any specific questions.
2.8 Hosting
This website is hosted externally. The personal data collected on this website is stored on the host's servers. This includes the automatically collected and stored log files (see below for more details), as well as all other data provided by website visitors.
External hosting is used for the purpose of secure, fast and reliable provision of our website and in this context serves to fulfill the contract with our potential and existing customers.
The legal basis for the processing is Art. 6 para. 1 lit. a, b and f GDPR, as well as § 25 para. 1 TDDDG, insofar as consent includes the storage of cookies or access to information in the terminal device of the website visitor or user within the meaning of the TDDDG.
Our hoster only processes data that is necessary to fulfill its performance obligations and acts as our Data Processor, i.e. it is subject to our instructions. We have concluded a corresponding Data Processing Agreement with our hoster.
We use the following hoster:
Strato
Strato AG, Otto-Ostrowski-Straße 7, 10249 Berlin.
https://www.strato.de/datenschutz/.
WiX
Wix.com Ltd, Nemal St. 40, 6350671 Tel Aviv, Israel.
https://de.wix.com/about/privacy.
2.9 Legal basis
The processing of personal data always requires a legal basis. The GDPR provides the following possibilities in Art. 6 para. 1 sentence 1:
a) The data subject has given their consent to the processing of their personal data for one or more specific purposes;
b) processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract;
c) the processing is necessary for compliance with a legal obligation to which the controller is subject;
d) processing is necessary in order to protect the vital interests of the data subject or of another natural person;
e) processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
f) processing is necessary for the purposes of the legitimate interests pursued by the controller(s) or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.
In the following sections, we will provide you with the specific legal basis for the respective processing.
3. What happens on our website
When you visit our website, we process your personal data.
We use SSL or TLS encryption to protect this data in the best possible way against unauthorized access by third parties. You can recognize this encrypted connection by the https:// or lock symbol in the address bar of your browser.
Below you can find out what data is collected when you visit our website, for what purpose this is done and on what legal basis.
3.1 Data collection when accessing the website
When you visit the website, information is automatically stored in so-called server log files. This is the following information:
• Browser type and browser version
• Operating system used
• Referrer URL
• Host name of the accessing computer
• Time of the server request
• IP address
This data is temporarily required in order to be able to display our website to you permanently and without any problems. In particular, this data is used for the following purposes:
• System security of the website
• System stability of the website
• Troubleshooting on the website
• Establishing a connection to the website
• Presentation of the website
Data processing is carried out in accordance with Art. 6 para. 1 lit. f GDPR and is based on our legitimate interest in the processing of this data, in particular our interest in the functionality of the website and its security.
Where possible, this data is stored in pseudonymized form and deleted once the respective purpose has been achieved.
If the server log files make it possible to identify the data subject, the data is stored for a maximum period of 14 days. An exception is made if a security-relevant event occurs. In this case, the server log files are stored until the security-relevant event has been resolved and finally clarified.
Otherwise, no merging with other data takes place.
3.2 Cookies
3.2.1 General information
This website uses so-called cookies. This is a data record, information that is stored in the browser of your end device and is related to our website.
The use of cookies can make it easier for visitors to navigate the website.
In our cookie consent tool you will find all information about the cookies that we use on our website (if applicable after your consent).
3.2.2 Rejecting cookies
You can manage all cookies that are not technically necessary directly via our cookie consent tool.
You can prevent cookies from being set by adjusting your browser settings.
Here you will find the corresponding links to frequently used browsers:
Mozilla Firefox: https://support.mozilla.org/de/kb/cookies-und-website-daten-in-firefox-loschen?redirectslug=Cookies+l%C3%B6schen&redirectlocale=en
Google Chrome: https://support.google.com/chrome/answer/95647?co=GENIE.Platform%3DDesktop&hl=de
Microsoft Edge: https://support.microsoft.com/de-de/windows/l%C3%B6schen-und-verwalten-von-cookies-168dab11-0753-043d-7c16-ede5947fc64d
Safari: https://support.apple.com/de-de/guide/mdm/mdmf7d5714d4/web and https://support.apple.com/de-de/guide/safari/sfri11471/mac.
Soweit If you use a different browser, we recommend that you enter the name of your browser and 'delete and manage cookies' in a search engine and follow the official link to your browser.
Alternatively, you can also manage your cookie settings at www.aboutads.info/choices/
oder www.youronlinechoices.com.
However, we must point out that a comprehensive blocking/deletion of cookies can lead to impairments in the use of the website.
3.2.3 Technically necessary cookies
We use technically necessary cookies on this website to ensure that our website functions correctly and in accordance with the applicable laws. They help to make the website user-friendly. Some functions of our website cannot be displayed without the use of cookies.
The legal basis for this is Art. 6 para. 1 lit. b, c and/or f GDPR, depending on the individual case.
3.2.4 Technically not necessary cookies
We also use cookies on our website that are not technically necessary. These cookies are used, among other things, to analyze the surfing behavior of the website visitor or to offer functions of the website that are not technically necessary.
The legal basis for this is your consent in accordance with Art. 6 para. 1 lit. a GDPR.
Technically unnecessary cookies are only set with your consent, which you can revoke at any time in the cookie consent tool.
3.3 Data processing through user input
3.3.1 Contact us
a) e-mail
When you contact us by email, we process your email address and any other data contained in the email. This data is stored on the mail server and in some cases on the respective end devices. Depending on the request, the legal basis for this is regularly Art. 6 para. 1 lit. f GDPR or Art. 6 para. 1 lit. b GDPR. The data will be deleted as soon as the respective purpose no longer applies and it is possible in accordance with the legal requirements.
b) Telephone
If you contact us by telephone, the call data may be stored in pseudonymized form on the respective end device and with the telecommunications provider used. Personal data collected during the telephone call will only be processed in order to process your request. Depending on the request, the legal basis for this is regularly Art. 6 para. 1 lit. f GDPR or Art. 6 para. 1 lit. b GDPR. The data will be deleted as soon as the respective purpose no longer applies and it is possible in accordance with the legal requirements.
c) Contact form
We offer a contact form. This is used to contact our company.
In this form, we usually process your first and last name, your telephone number, your e-mail address, a postal address and the content of the message. The data is stored on our web server and forwarded internally to the relevant e-mail addresses.
The legal basis for data processing is Art. 6 para. 1 lit. f GDPR, as we have a legitimate interest in responding to your request and in an uncomplicated way of contacting you. If the contact is aimed at the conclusion of a contract, the additional legal basis for the processing is Art. 6 para. 1 lit. b GDPR.
We delete this data no later than 3 months after receipt, unless it is required for a contractual relationship that has arisen.
We bind the contact form from
Wix
Wix.com Ltd, Nemal St. 40, 6350671 Tel Aviv, Israel
https://de.wix.com/about/privacy
on our website.
d) Appointment scheduling tool
3.4 Cookie Consent Tool
3.4.1 Usercentrics
We use the consent management tool from Usercentrics GmbH, Sendlinger Str. 7, 80331 Munich, Germany, to ensure that only those cookies are set on our website for which there is a legal basis.
This service is used to obtain the website visitor's consent to the storage of certain cookies in their browser or the use of certain technologies and to document them in accordance with data protection regulations.
When this website is accessed, the consent given by the website visitor or the revocation of consent is stored as a Usercentrics cookie in the browser of the website visitor. A connection to the Usercentrics servers is established for this purpose.
The legal basis is Art. 6 para. 1 lit. c GDPR. Usercentrics is used to obtain the legally required consent for the use of cookies.
If the Usercentrics consent management tool is integrated into the website via a third-party provider, data (e.g. IP address) may be transmitted to the third-party provider.
The data collected will be stored until the website visitor requests its deletion or Usercentrics deletes it itself or the purpose for storing the data no longer applies. The mandatory statutory retention periods remain unaffected by this.
3.5 Website construction kit system
3.5.1 Wix
We use the Wix service to create our website. This is a service of Wix.com Ltd, Namal 40, 6350671 Tel Aviv, Israel.
Wix is a website builder system that can be used to create HTML5 websites and mobile websites. It is an online platform that is based on the cloud principle. This makes it very easy to integrate the functions into your own website. With this service, we can design our website according to our wishes and meet our goal of user-friendliness.
Wix uses cookies. These cookies are only set with the consent of the website visitor and can be revoked at any time. The legal basis for the processing is Art. 6 para. 1 lit. a GDPR.
Furthermore, the use of the service is technically necessary for us to display our website. The legal basis for the processing is Art. 6 para. 1 lit. f GDPR.
The data will be deleted as soon as it is no longer required for the processing purposes.
Further information:
https://de.wix.com/about/privacy.
3.6 Analysis and tracking tools
3.6.1 WIX Analytics
We integrate the analytics functions of Wix on our website. This service is offered by wix.com Ltd, Nemal St. 40, 6350671 Tel Aviv, Israel.
Wix Analytics collects and stores various types of user data for optimization and marketing purposes. This data is anonymized and summarized in statistical reports. The information collected includes login data, time zone settings, operating system and platform used, details of website visits such as the URL, duration of use, number of pages visited per session, search terms entered, information about interactions on the website, such as content searched for or viewed, page response speed and conversion rate.
Wix Analytics uses cookies for this purpose. The legal basis for the processing is Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG, insofar as this consent includes access to information in the user's terminal device or the storage of cookies within the meaning of the TDDDG.
Otherwise, the legal basis for the processing is Art. 6 para. 1 lit. f GDPR. We have a legitimate interest in the analysis to ensure the technical stability of our website.
Further information:
https://de.wix.com/about/privacy.
3.7 Third-party content
3.7.1 Google Fonts
We have integrated Google Fonts locally on our server. This means that no data is transferred to Google, despite its use.
3.7.2 WIX CDN
We use the CDN from WIX. This service is provided by wix.com Ltd, Nemal St. 40, 6350671 Tel Aviv, Israel.
Ein Content Delivery Network (CDN) ist ein verteiltes Netzwerk von Servern, das dazu dient, Webinhalte wie Webseiten, Bilder und Videos schneller an Nutzer zu liefern, indem es die Daten von einem geografisch näher am Nutzer gelegenen Server bereitstellt. Dies verringert die Ladezeiten und verbessert die Nutzererfahrung, während es gleichzeitig die Webseiten vor hohen Verkehrslasten und Sicherheitsbedrohungen schützt.
Für diesen Zweck werden personenbezogene Daten an WIX weitergeleitet.
Rechtsgrundlage ist Art. 6 Abs. 1 lit. f DSGVO. Wir haben ein berechtigtes Interesse daran die Sicherheit und Auslieferungsgeschwindigkeit unserer Website zu erhöhen und ein CDN zu nutzen.
Diese Daten werden so lange gespeichert, bis the data subject zur Löschung auffordert, die Einwilligung zur Speicherung widerrufen wurde oder der Zweck für die Speicherung entfallen ist.
Weitere Informationen:
https://de.wix.com/manage/privacy-security-hub.
https://de.wix.com/about/privacy.
3.7.3 Wix Multilingual
Wir nutzen auf unserer Website Wix Multilingual, einen Dienst zur Erstellung mehrsprachiger Websites, bereitgestellt von Wix.com Ltd., 40 Namal Tel Aviv St., Tel Aviv, Israel.
Wix Multilingual ermöglicht es uns, unsere Website in mehreren Sprachen anzubieten und somit ein internationales Publikum zu erreichen.
Bei der Nutzung von Wix Multilingual werden Daten wie Sprachpräferenzen und technische Informationen wie IP-Adresse und Browsertyp verarbeitet.
Die Datenverarbeitung erfolgt zum Zweck der Bereitstellung einer mehrsprachigen Website und Verbesserung der Nutzererfahrung.
Rechtsgrundlage für die Datenverarbeitung ist Art. 6 Abs. 1 lit. f DSGVO aufgrund unseres berechtigten Interesses an der internationalen Ausrichtung unserer Website.
Wix Multilingual kann Cookies zur Speicherung von Spracheinstellungen setzen. Diese Cookies werden nur mit Einwilligung gesetzt und können jederzeit in unserem Cookie-Consent-Tool widerrufen werden. Rechtsgrundlage hierfür ist Art. 6 Abs. 1 lit. a DSGVO und § 25 Abs. 1 TDDDG.
Es findet eine Datenübermittlung in ein Drittland, nämlich nach Israel, statt. Israel verfügt über einen Angemessenheitsbeschluss der Europäischen Kommission, sodass ein angemessenes Datenschutzniveau gewährleistet ist.
Die Daten werden gespeichert, bis zur Löschung auffordert wird, die Einwilligung widerrufen wird oder der Zweck für die Speicherung entfällt. Gesetzliche Aufbewahrungsfristen bleiben unberührt.
Weitere Informationen zur Datenverarbeitung finden sich unter:
https://de.wix.com/about/privacy.
3.8 Audio and video conferencing
3.8.1 Microsoft Teams
We use Microsoft Teams to communicate with customers. Microsoft Teams is an online conferencing tool. This service is provided by Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland.
When communicating with this tool via video or audio conferencing, personal data is processed by us and the provider of the tool. The data collected includes all information that you provide when using the tool. Metadata relating to the conference is also processed. Furthermore, technical information is processed that is required for the function of online communication. Furthermore, all files that are shared within the tool are stored on the tool provider's servers.
Microsoft Teams can also set cookies. These cookies are only set with consent. This consent can be revoked at any time. The legal basis for this is Art. 6 para. 1 lit. a GDPR.
Otherwise, the legal basis for the processing of data by Microsoft Teams is Art. 6 para. 1 lit. b GDPR. The communication is related to the performance of a contract or is necessary for the fulfillment of pre-contractual obligations. Furthermore, this tool is used to simplify communication with our company. This constitutes a legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR.
This data is stored until the data subject requests its deletion, the consent to its storage is revoked or the purpose for its storage no longer applies. Cookies remain on the end device until the user deletes them. Mandatory statutory provisions on retention periods remain unaffected.
Further details:
https://privacy.microsoft.com/de-de/privacystatement.
3.9 Cloud backups
We use cloud backup functions on our website to protect the data and content of the website from data loss, corruption or security incidents. This ensures that the website can be restored quickly and completely in the event of a server failure, a hacker attack or other unforeseen events.
Sofern auf unserer Website personenbezogene Daten hinterlegt sind, werden diese bei den Backups auf die Server des jeweiligen Anbieters übertragen.
Die Rechtsgrundlage für die Datenverarbeitung ist Art. 6 Abs. 1 lit. f DSGVO, da wir ein berechtigtes Interesse an der Sicherung unserer Daten haben.
We use the following cloud backup service:
WIX CMS Backup
Wix.com, Inc., 500 Terry A. Francois Boulevard, 6th Floor, San Francisco, CA 94158, USA.
https://support.wix.com/en/article/wix-privacy-policy.
4. What else is important
Finally, we would like to inform you in detail about your rights and how you will be informed about changes to data protection requirements.
4.1 Your rights in detail
4.1.1 Right to information in accordance with Art. 15 GDPR
You can request information about whether your personal data is being processed. If this is the case, you can request further information on the type and manner of processing. A detailed list can be found in Art. 15 para. 1 lit. a to h GDPR.
4.1.2 Right to rectification in accordance with Art. 16 GDPR
This right includes the correction of incorrect data and the completion of incomplete personal data.
4.1.3 Right to erasure in accordance with Art. 17 GDPR
This so-called 'right to be forgotten' gives you the right, under certain conditions, to request the deletion of personal data by the controller. This is generally the case if the purpose of the data processing no longer applies, if consent has been withdrawn or if the initial processing took place without a legal basis. A detailed list of reasons can be found in Art. 17 para. 1 lit. a to f GDPR. This "right to be forgotten" also corresponds to the controller's obligation under Art. 17 para. 2 GDPR to take reasonable steps to ensure that the data is generally erased.
4.1.4 Right to restriction of processing in accordance with Art. 18 GDPR
This right is subject to the conditions set out in Art. 18 para. 1 lit. a to d.
4.1.5 Right to data portability in accordance with Art. 20 GDPR
This regulates the basic right to receive your own data in a commonly used form and to transfer it to another controller. However, this only applies to data processed on the basis of consent or a contract in accordance with Art. 20 (1) (a) and (b) and insofar as this is technically feasible.
4.1.6 Right to object pursuant to Art. 21 GDPR
In principle, you can object to the processing of your personal data. This applies in particular if your interest in objecting outweighs the legitimate interest of the controller in the processing and if the processing relates to direct marketing and/or profiling.
4.1.7 Right to "individual decision-making" pursuant to Art. 22 GDPR
In principle, you have the right not to be subject to a decision based solely on automated processing (including profiling) which produces legal effects concerning you or similarly significantly affects you. However, this right is also restricted and supplemented by Art. 22 (2) and (4) GDPR.
4.1.8 Further rights
The GDPR contains comprehensive rights to inform third parties about whether or how you have asserted rights under Art. 16, 17, 18 GDPR. However, this only applies insofar as this is possible or feasible with reasonable effort.
We would like to take this opportunity to draw your attention once again to your right to withdraw your consent in accordance with Art. 7 (3) GDPR. However, this does not affect the lawfulness of the processing carried out up to that point.
We would also like to draw your attention to your rights under §§ 32 ff. BDSG, which, however, are largely congruent with the rights just described.
4.1.9 Right to lodge a complaint pursuant to Art. 77 GDPR
You also have the right to lodge a complaint with a data protection supervisory authority if you consider that the processing of personal data relating to you infringes this Regulation.
5. What if the GDPR is abolished tomorrow or other changes take place?
The current status of this Privacy Policy is 28.05.2025. From time to time it is necessary to adapt the content of the Privacy Policy to respond to factual and legal changes. We therefore reserve the right to amend this Privacy Policy at any time. We will publish the amended version in the same place and recommend that you read the Privacy Policy regularly.
Created with the kind support of Dieter macht den Datenschutz