Privacy Policy

Privacy Policy of DRF Aviation Services GmbH


DRF Aviation Services GmbH is pleased to welcome you to our website and appreciates your interest in our company. We take the protection of your personal data very seriously. We process personal data collected when you visit our website confidentially and in accordance with the applicable data protection regulations. Protecting your privacy when processing personal data is an important concern for us, which we take into account in our business processes.

The following information explains how we collect and process personal data when you use our website. Personal data means any information relating to an identified or identifiable individual, such as your name, address, email address or user behaviour.

Controller Responsible for Data Processing


The controller responsible within the meaning of Art. 4(7) of the General Data Protection Regulation (GDPR) is:

DRF Aviation Services GmbH
Rita-Maiburg-Straße 2
70794 Filderstadt
Germany

Tel.: +49 711 7007 0
E-Mail: datenschutz@drf.de
Website: https://drf-aviationservices.de/

Hosting

Our website is hosted in the Hetzner Cloud at a data centre located in Nuremberg, Germany. Data processed on our server as part of the hosting service is processed within the European Union.

The hosting provider, Hetzner Online GmbH, is certified according to DIN ISO/IEC 27001:2022 and holds a BSI C5 Type 2 attestation for its cloud services.

Data Protection Officer


Althammer & Kill GmbH & Co. KG
Roscherstraße 7
30161 Hannover

Germany

Tel.: +49 511 330603-90
Email: kontakt-dsb@althammer-kill.de

Collection and Use of Your Data


The scope and nature of the collection and use of your personal data differs depending on whether you visit our website solely to access information or make use of any services we may offer.

If we use additional (IT) service providers for individual functions of our services or intend to use your data for advertising purposes, we will provide you below with detailed information about the respective processes (all data processing activities). We will also specify the criteria established for the storage period and the applicable legal basis for the data processing.

Informational Use:

When using our website for informational purposes, we only collect the personal data that your browser automatically transmits to us, such as:

  • IP address
  • Date and time of the request
  • Time zone difference from Greenwich Mean Time (GMT)
  • Content of the request (specific page)
  • Data volume transferred and access status (file transferred, file not found, etc.)
  • Website from which the request originates
  • Browser type / version / language
  • Operating system and its interface
  • Language and version of the browser

Storage Period:

The server/access logs are stored for a period of 90 days.

Legal Basis for Data Processing:

The above-mentioned data is technically necessary to display our website to you and to ensure its stability and security, pursuant to Art. 6(1)(f) GDPR.

Cookies


We use cookies on our website. Cookies are small text files that are sent to your browser by our web server when you visit our website and stored on your computer for later retrieval. They are used to make our website more user-friendly and effective overall.

Cookies can generally be divided into two categories:

Transient cookies are automatically deleted when you close your browser. These include session cookies in particular. They store a so-called session ID, which allows different requests from your browser to be assigned to the same session. This enables your computer to be recognised when you return to the website. Session cookies are deleted when you log out or close your browser.

Persistent cookies are automatically deleted after a predefined period, which may vary depending on the cookie. You can delete cookies at any time in your browser's security settings.

Cookies serve various functions. Many cookies are technically necessary because certain website functions would not work without them. These cookies are stored on the basis of Art. 6(1)(f) GDPR, unless another legal basis is specified. We have a legitimate interest in storing necessary cookies to ensure the technically error-free and optimised provision of this website. Other cookies may be used to analyse user behaviour, for advertising purposes or in connection with other additional functions. These cookies are only used on the basis of your consent pursuant to Art. 6(1)(a) GDPR and Section 25 TDDDG; you may withdraw your consent at any time.

Job Applications


You have the option of applying for open positions at DRF Aviation Services GmbH via our online application form. Your application documents are transmitted in encrypted form.

Using the “Apply with finest jobs profile” function, you can also apply using an existing finest jobs profile. The data stored in your profile can be transferred to your application.

As part of the application process, we process the data you provide, in particular your personal data and the application documents you submit. This may include, for example, cover letters, CVs and certificates.

The data collected as part of the application process is only accessible to those internal departments and individuals who are involved in processing your application and filling the respective position.

You can also submit unsolicited applications via our application portal.

Service Providers

We use the services of rexx systems GmbH to carry out the application process. rexx systems GmbH provides the applicant management system. As part of providing, maintaining and supporting the system, rexx systems GmbH may have access to personal data.

Storage Period

If your application is rejected, your application data will be deleted six months after the application process has been completed, unless a longer storage period is required by law or for the assertion, exercise or defence of legal claims.

If you have consented to being included in our applicant pool, your application data will be stored for a period of 12 months.

If an employment relationship is established with you following the application process, the data required for the employment relationship will be transferred to the personnel information system designated for this purpose.

Your application data is processed for the purpose of carrying out the application process on the basis of Section 26(1) of the German Federal Data Protection Act (BDSG). Inclusion in the applicant pool is based on your consent pursuant to Art. 6(1)(a) GDPR. Where processing is necessary for the assertion, exercise or defence of legal claims, processing may be based on Art. 6(1)(f) GDPR.

Applying via WhatsApp

You can continue to apply via WhatsApp. The processing of your data as part of an application via WhatsApp is based on your consent pursuant to Art. 6(1)(a) GDPR.

Please note that when using WhatsApp, it cannot be ruled out that personal data may be processed outside the European Union. Further information on data protection at WhatsApp can be found in WhatsApp's Privacy Policy.

You may withdraw your consent to applying via WhatsApp at any time with effect for the future.

Applications via WhatsApp are processed through the technical integration of the applicant management system provided by rexx.

Privacy Settings / Consent Management Tool


When you first visit this website, you have the option of configuring your privacy and third-party service settings in the consent manager according to your preferences and refusing the acceptance or placement of certain cookie categories, such as marketing cookies, as well as the transfer of data to certain third-party services. Please note, however, that you may then not be able to use all functions of our website.

The settings you have selected will be stored for future sessions unless you delete the relevant cookies. In this case, you will be asked to configure your individual privacy settings again when you revisit our website.

Usercentrics Consent Management:

To obtain your consent to the storage of certain cookies or the use of certain technologies and to document this consent in compliance with data protection requirements, we use the Consent Management Platform (CMP) provided by Usercentrics GmbH, Sendlinger Str. 7, 80331 Munich, Germany (hereinafter “Usercentrics”).

Usercentrics enables the collection, management and documentation of your consent decisions and any changes to them. The Usercentrics CMP is used for DRF Aviation Services GmbH with its own configuration. Cross-Domain Consent Sharing is disabled. Consent decisions collected via the CMP are not shared with other companies within the DRF Group.

The technologies used on our website are controlled via the CMP in accordance with your consent decision. The categories “Essential” and “Statistics/Analytics” are currently configured.

Contact Forms


When you contact us via one of our contact forms or by email, we store the data you provide (e.g. your name, email address, subject and message) in order to respond to your questions and requests. Mandatory information required for this purpose is marked separately. Providing additional information is voluntary. When you submit your message, your IP address as well as the date and time of your message are also recorded.

Storage Period:

We delete the data collected in this context once it is no longer required or your request has been fully processed, or restrict its processing if statutory retention obligations apply (up to ten years where necessary for the retention and archiving of business email correspondence in accordance with commercial and tax law).

Legal Basis for Data Processing:

Data processing is generally carried out pursuant to Art. 6(1)(b) GDPR for the implementation of pre-contractual measures and pursuant to Art. 6(1)(f) GDPR based on our legitimate interest in processing your request.

Web Analytics with Matomo


We use Matomo on our website for the statistical analysis of website usage and to improve our online services. Matomo is operated for DRF Aviation Services GmbH in a technically separate environment from other companies within the DRF Group.

Processing is carried out on the basis of your consent pursuant to Art. 6(1)(a) GDPR. Consent is obtained via our consent management system, Usercentrics, and can be withdrawn there at any time with effect for the future.

When using Matomo, IP addresses are anonymised. Two bytes of the IP address are anonymised for this purpose. The anonymised IP address is also used to process visitor data. User IDs are pseudonymised. Referrer URLs are anonymised by removing any query parameters contained in them.

The raw data collected by Matomo is deleted after 744 days. Aggregated report data is not automatically deleted.

Matomo Cloud is provided by InnoCraft Ltd., 7 Waterloo Quay, PO Box 625, 6140 Wellington, New Zealand. Data processed as part of Matomo Cloud is stored in data centres within the European Union, particularly in Frankfurt am Main; backups are stored in Dublin. The transfer of personal data to InnoCraft Ltd. in New Zealand is based on the European Commission's adequacy decision pursuant to Art. 45(3) GDPR.

Contracts Concluded with DocuSign Germany GmbH


For the digital conclusion of contracts, we use the services of DocuSign Germany GmbH (DocuSign).

In this context, DocuSign processes the following personal data: (user) name, business email address and telephone number, the electronic signature used and authentication data, activity and document logs, transaction metadata, IP addresses, other online identifiers and location data, as well as personal data contained in the individual contracts.

Purpose and legal basis of processing:

We use DocuSign to simplify, accelerate and optimise the signing process. The legal basis for processing is our legitimate interest pursuant to Art. 6(1)(f) GDPR.

The use of an electronic signature is voluntary for the contractual partner. Contracts, agreements and similar documents may also continue to be concluded in non-digital form. The further legal basis for this is consent pursuant to Art. 6(1)(a) GDPR.

Recipients of personal data; data transfers to third countries:

The individual documents uploaded are encrypted and can only be accessed by the persons designated in advance.

Personal data is processed by the relevant contacts within the DRF departments with whom the contractual partners are in contact.

DocuSign is responsible for all maintenance activities and for ensuring the proper functioning of the electronic signature. Sub-processors are listed on the DocuSign website.

Personal data may be processed in third countries. Appropriate safeguards have been provided by DocuSign for such transfers.

Storage period:

Personal data contained in signed documents is stored until the purposes specified in the respective agreements have been fulfilled and the applicable statutory and contractual retention periods have expired.

Personal data processed via DocuSign is automatically deleted 120 days after the counter-signature.

Your Rights


You have the following rights with regard to your personal data:

  • Right of access
  • Right to rectification or erasure
  • Right to restriction of processing
  • Right to data portability

Right to lodge a complaint with a supervisory authority:

You also have the right to lodge a complaint with a data protection supervisory authority regarding the processing of your personal data by us.

State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg
Heilbronner Straße 35
70191 Stuttgart
Germany
Phone: +49 711 615541-0
Email: poststelle@lfdi.bwl.de
Website: www.baden-wuerttemberg.datenschutz.de

Right to Object and Right to Withdraw Consent:

If you have given your consent to the processing of your data, you may withdraw your consent at any time. Such withdrawal affects the lawfulness of the processing of your personal data after you have communicated your withdrawal to us.

Where we base the processing of your personal data on a balancing of interests (the legal basis being Art. 6(1)(f) GDPR), you may object to the processing. This applies where the processing is not necessary, in particular, for the performance of a contract with you. We will indicate this in the explanations of the individual data processing activities and functions on our website above in this Privacy Policy. If you exercise such a right to object, please explain the reasons why we should not process your personal data as we do. In the event of a justified objection, we will review the situation and either stop or adjust the data processing, or provide you with our compelling legitimate grounds for continuing the processing.

Contact Options Regarding Your Rights:

You may contact us at any time to exercise your rights. Please use the following email addresses:

You may also use any of the contact details provided in our Legal Notice or contact our Data Protection Officer directly.

Data Security


We also implement technical and organisational security measures to protect personal data that is collected or processed, in particular against accidental or intentional manipulation, loss, destruction or access by unauthorised persons. Our security measures are continuously improved in line with technological developments.

The transmission of your personal data is encrypted using SSL technology (HTTPS) to prevent unauthorised third-party access.

Communication by Email


Our email systems support encrypted communication using SSL technology. Your email can therefore generally be transmitted in encrypted form. However, please note that encryption also depends on the configuration of your email client, and we therefore cannot guarantee complete data security during transmission.

For information requiring a high level of confidentiality, we recommend sending it by post.