Skip to content

Legal

Privacy policy

This page is an automated translation provided for convenience. Only the German version is legally binding and governed by German law.

Thank you for your interest in DAT AUTOHUS. Protecting your personal data is important to us. Below we explain how your data is processed when you use our website and our app.

This English translation is provided for convenience only. The German version is legally binding.

Controller

DAT AUTOHUS AG
An der Autobahn 11

27404 Bockel

Germany

Email: vertrieb@autohus.de
Website: www.autohus.de

Tel.: +49 4286 / 926 0

Fax: +49 4286 / 926 499

Data protection officer

Dr. jur. Kay Gunkel
Universitätsallee 5
28359 Bremen
Deutschland

Email: kontakt@ra-gunkel.de · dsb@autohus.de

Hosting and server log files

You can visit our website without providing any personal details. Each time it is accessed, your browser or our app transmits technical usage data that is stored in log files (server log files). This includes in particular your IP address, the date and time of the request, the address accessed including any parameters, the result of the request, the volume of data transferred, the previously visited page (referrer) and the identifier of your browser or operating system. This data serves to ensure trouble-free operation, to defend against attacks and to investigate misuse.

The website, the app interface and the associated databases are operated for us by a contractually bound processor (Art. 28 GDPR) on the infrastructure of Amazon Web Services (AWS). Servers, databases and log storage are located in the AWS Frankfurt am Main region. The pages are delivered via the Amazon CloudFront content delivery network, which answers each request at a network node as close to you as possible — for requests from Europe, generally in Europe. Requests first pass through a web application firewall (AWS WAF), which checks them for attack patterns. We send emails to you (e.g. confirmation codes, reservation and order confirmations) via Amazon Simple Email Service in the Frankfurt am Main region. The legal basis is Art. 6(1)(f) GDPR, based on our legitimate interest in a secure and functioning web presence; where emails serve the performance of a contract, Art. 6(1)(b) GDPR.

How long we retain log data depends on its type:

Access logs of the content delivery network (every request, without cookies): stored in Frankfurt am Main, automatically deleted after 90 days.

Web application firewall logs: these contain only requests that triggered a security rule — which may include ordinary requests, for example from data-centre networks or anonymisation services — with the IP address, the address accessed and the request headers, but without cookies and login credentials. For technical reasons, these logs are stored in the AWS US East (N. Virginia) region and automatically deleted after 90 days.

Logs of our application programming interface: every request that changes data (e.g. registration, login, reservation, order, form submission) and every failed request is logged with the IP address, browser identifier, address accessed, result and — for logged-in users — the email address of the customer account. This takes place, firstly, as a log line in Frankfurt am Main, which is deleted automatically after 90 days, and, secondly, as an entry in our database in Frankfurt am Main, which we delete automatically after twelve months. Backup copies of the database are kept for 35 days.

If log data is needed to investigate a specific security incident, we retain it until the incident has been resolved. For the storage of the firewall logs in the USA, we rely on the European Commission's adequacy decision on the EU-US Data Privacy Framework, under which Amazon Web Services is certified; the standard contractual clauses of the data processing agreement with AWS apply in addition.

Crash reports: If a program error occurs on our website or in our app, it sends an error report to our server. The report contains the error text, the technical program sequence at the point of the error, the affected area, the platform and, for the website, the address accessed. We log it as described above under “Logs of our application programming interface”, subject to the same deletion periods, and use it exclusively to find and fix errors (Art. 6(1)(f) GDPR).

Contact form

When you use the contact form, we collect your personal data (name, contact details, message) only to the extent you provide it. The processing serves the purpose of getting in touch with you and is carried out on the basis of Art. 6(1)(a) GDPR with your consent, and additionally on the basis of Art. 6(1)(b) GDPR for contract-related enquiries.

You may withdraw your consent at any time by notifying us, without affecting the lawfulness of processing carried out up to the point of withdrawal. We use your contact details only to handle your enquiry. For further processing and retention periods, see the section “Customer enquiries and lead handling (CRM)”.

Customer account (“Mein Parkplatz”)

When you open a customer account, we collect the data entered there (name, email address, password, and optionally telephone number, address and company details) as well as the time and language of registration. The customer account makes your shortlist, saved searches, enquiries, reservations, vehicle sale submissions and orders available to you on the website and in the app. The legal basis is Art. 6(1)(b) GDPR (contract of use for the customer account). We store your password exclusively as a cryptographic hash; a login remains valid for no more than 90 days.

You can delete your customer account at any time — how to do so, and which accounts we delete automatically, is described in the section “Deleting your customer account”. If a purchase contract or similar is concluded, storage of the contract data is governed by the retention periods under commercial and tax law (§ 257 HGB, § 147 AO).

If you reserve a vehicle, we store the reservation (vehicle, start and end) in your customer account. To ensure that the vehicle is not sold to someone else at the same time, we transfer your name or company name, your email address and — where provided — your telephone number to our internal inventory management system, in which our sales team sees the reservation (Art. 6(1)(b) GDPR). Reservations are subject to a fee and are paid in advance via our payment service provider (see “Online payment (Stripe)”). If we offer a free reservation period, we store for 30 days after it has ended the fact that you had already reserved this vehicle, so that it can be used only once per vehicle (Art. 6(1)(f) GDPR).

Newsletter

Independently of any contract, we use your email address exclusively for our own promotional purposes to send our newsletter, provided you have expressly agreed to this (Art. 6(1)(a) GDPR). There are two ways to sign up: via the sign-up form on the website, the double opt-in procedure applies — you receive an email with a confirmation link, and we add you to the distribution list only after you have clicked it; unconfirmed sign-ups are deleted after 30 days. In your customer account (by ticking the box during registration or using the switch in the account settings), the second confirmation email is not required because you have already confirmed your email address for the account; a box ticked during registration takes effect only upon that confirmation. As proof of your consent, we store the time and IP address of the sign-up and of the confirmation, as well as the sign-up method.

You may withdraw your consent at any time without affecting the lawfulness of processing carried out up to the point of withdrawal — via the unsubscribe link in every newsletter, via the switch in your customer account or by notifying us. You will then no longer receive the newsletter. Your email address remains stored with the note “unsubscribed” and the time of unsubscription so that we can respect your withdrawal and demonstrate the earlier consent (Art. 6(1)(f) GDPR); we delete this note — including at our mailing service provider — three years after you unsubscribe. We use CleverReach to send the newsletter (see the section “Newsletter delivery via CleverReach”).

Vehicle assistant (chat)

The assistant on our website answers questions about vehicles and our stock. It is an AI system: the answers are generated by a language model (Claude from the provider Anthropic), which we use via the Amazon Bedrock service in our own AWS account. For this purpose your input is transmitted to our backend and passed from there to Amazon Bedrock in the Frankfurt am Main region; via the European inference profile of Amazon Bedrock, the computation may be distributed across AWS data centres in other regions within the European Union. Processing therefore takes place within the EU. According to AWS, the model provider does not receive the content, and it is not used to train models.

So that we can improve the assistant, find errors in its answers and detect misuse, we store the conversations on our website for 30 days, counted from the last message; after that they are deleted automatically. We store your input, the assistant's answers, the time, the selected language and whether you were signed in to your customer account — not your IP address, not your browser identifier and no link to your customer account. Conversations are assigned only to a random identifier that your browser creates for the respective conversation. Before storing, we automatically make e-mail addresses, telephone numbers, IBANs, vehicle identification numbers and number plates unrecognisable. We do not pass the stored conversations on to our sales team; only a small number of authorised persons can analyse them. As we do not assign the conversations to any person, we are generally unable to attribute them to a specific request (Art. 11 GDPR).

The conversation history is also held in your browser's session storage and is sent along with each question so that the assistant knows the context. There it is deleted when you close the tab, restart the chat or do not write anything for four hours. Our servers log every chat request without its content (time, IP address, browser identifier, result; retention as described under “Hosting and server log files”). To prevent misuse, we count the requests per day under a hash of your IP address; this counter is deleted after two days. The legal basis is Art. 6(1)(f) GDPR, based on our legitimate interest in an advisory function that works reliably and is protected against abuse. You may object to the processing at any time on grounds relating to your particular situation (Art. 21 GDPR). Please do not enter sensitive data in the chat — for binding information, please use the contact channels.

If you ask in the chat, via “Ask sales to contact me”, for our sales team to get in touch with you, we transmit your name, the e-mail address or telephone number you enter there and the conversation so far to our sales team; this information is not made unrecognisable. This allows the team to prepare for your request before contacting you. We process the request like a message sent via our contact form (Art. 6(1)(a) GDPR with your consent and, for contract-related requests, additionally Art. 6(1)(b) GDPR); details can be found in the section “Contact form”. Without such a request, we do not pass any conversation on to sales.

Cookies and local storage

Our website uses cookies and comparable storage techniques in the browser (localStorage). We use them to retain your language setting, your shortlist, the vehicle comparison, the tyre search basket and an existing login across page changes. This storage is strictly necessary for the functions you have expressly requested to work; it does not require consent under § 25(2) no. 2 TDDDG. We base the associated processing on Art. 6(1)(f) GDPR.

Storage that is not strictly necessary takes place only with your consent — currently this concerns exclusively the interest profile described below (§ 25(1) TDDDG, Art. 6(1)(a) GDPR). We do not use any third-party advertising, tracking or analytics services: no Google Analytics, no Facebook or TikTok pixel, no ad networks.

Storage takes place on your device — you have full control over it. Using your browser settings you can restrict or prevent cookies from being set and delete stored cookies at any time. Please note that not all functions of this website may then be fully usable.

Fonts (Adobe Fonts)

To display the website we embed fonts from the Adobe Fonts service provided by Adobe Inc. (345 Park Avenue, San José, CA 95110-2704, USA). When a page is loaded, your browser retrieves the font files from one of the provider's servers, in the course of which your IP address is transmitted to Adobe. Your IP address may be transferred to the USA in the process. According to the provider, the data is not used for profiling and Adobe does not set cookies for the delivery of fonts.

The legal basis is Art. 6(1)(f) GDPR, based on our legitimate interest in a consistent and accessible presentation of our offering. For data transfers to the USA we rely on the European Commission's adequacy decision on the EU-US Data Privacy Framework; the standard contractual clauses apply in addition. Further information: adobe.com/privacy/policy.html

YouTube videos

On individual pages we embed videos from YouTube (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). As long as you do not start a video, no connection whatsoever to YouTube is established — all that is visible is a preview image hosted by us. Only when you click the play button is the player loaded in enhanced privacy mode (youtube-nocookie.com) and data, in particular your IP address, transmitted to YouTube.

The legal basis for loading it is your consent given by clicking the play button (Art. 6(1)(a) GDPR, § 25(1) TDDDG). We have no influence over the processing that takes place there. For details see Google's privacy notices: policies.google.com/privacy

Map links (Google Maps)

We do not embed Google Maps into our pages. On the “Locations” page you will find nothing more than ordinary links to Google Maps. Only when you click such a link do you leave our website and data is transmitted to Google; Google's privacy notices then apply (policies.google.com/privacy). As long as you do not click, no connection to Google is established.

Social networks

In the footer we link to our profiles on Facebook, Instagram, TikTok, LinkedIn and XING. These are plain links, not social plugins or pixels: simply visiting our website transmits no data to these networks and your visit cannot be attributed to any account there. Only when you click a link do you reach the providers' own pages, whose processing is governed by their own privacy policies.

Online payment (Stripe)

You can pay online for chargeable services on our website and in our app — currently the reservation of a vehicle including its extension and the purchase of wheel sets in the tyre centre. Payments are processed by Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland (“Stripe”). The checkout is either embedded in our page — we load the Stripe program library required for this only when you open the checkout — or displayed on a Stripe page; from the app, it opens in a browser window.

In this context, we and Stripe process the following data: name, email address, billing address, for shipments the delivery address, the order data (vehicle and number of days, or item numbers; for tyre purchases, the manufacturer and type codes from the vehicle registration certificate), amount, language and the payment data entered in the checkout. You enter your card or account details directly with Stripe; we do not receive them. Stripe creates a customer profile for your email address. If you select a payment method of another provider in the checkout, Stripe transmits the data required for the payment to that provider; that provider's privacy notices then apply in addition.

The legal basis is Art. 6(1)(b) GDPR (performance of the contract). Stripe processes certain data as an independent controller, for example to prevent fraud and to comply with legal obligations. For this purpose, Stripe uses cookies or comparable identifiers in the checkout that are necessary for the payment you have requested (§ 25(2) no. 2 TDDDG). Stripe may transfer data to Stripe, Inc. in the USA; such transfers are covered by the European Commission's adequacy decision on the EU-US Data Privacy Framework, under which Stripe, Inc. is certified, and standard contractual clauses apply in addition. Further information: stripe.com/privacy

We retain payment and invoice data in accordance with the retention periods under commercial and tax law (§ 257 HGB, § 147 AO) and delete it ten years after the end of the calendar year in which the payment was made; until then, invoices are archived in unalterable form. Checkout sessions that are not paid are deleted from our system after seven days.

Newsletter delivery via CleverReach

We send the newsletter via CleverReach GmbH & Co. KG, Schafjückenweg 2, 26180 Rastede, Germany (“CleverReach”), which acts as our processor (Art. 28 GDPR). As soon as your sign-up has been confirmed — via the confirmation link or via your customer account — we transmit your email address, your language and the time of sign-up to CleverReach. The legal basis is your consent (Art. 6(1)(a) GDPR).

CleverReach analyses whether a newsletter was delivered and opened and which links in it were clicked; for this purpose, the newsletters contain a tracking pixel and links that are routed via CleverReach. We see this analysis in aggregated form per mailing and use it to improve the newsletter. The analysis is part of the newsletter to which you have consented; if you withdraw your consent, the analysis ends as well.

If you unsubscribe — via the unsubscribe link in the newsletter, in your customer account or by notifying us — your email address is flagged as unsubscribed at CleverReach and no longer receives the newsletter. Unsubscriptions received directly by CleverReach are synchronised with our system every hour.

VIN scan and registration certificate in the app

If you offer us a vehicle for purchase in the app, you can photograph the vehicle identification number (VIN) instead of typing it in. The photo is transmitted to our backend and passed from there to an AI model for image recognition (Claude from the provider Anthropic, used via Amazon Bedrock; request to the Frankfurt am Main region, processing via the European inference profile within the EU), which reads the 17 characters. The photo is not stored in the process — neither by us nor for training models. The recognised VIN is returned only to the app; we do not write it to our logs. It is stored only when you submit your vehicle sale request.

If you photograph the vehicle registration certificate, further details may be visible in the image, such as the name and address of the registered keeper. These, too, are transmitted solely for recognition and are not stored; please cover them where possible. Use of the scan is voluntary; you can enter the VIN manually at any time. The VIN scan is only available with a confirmed customer account; to limit misuse, we count the scans per customer account and day (email address and number) and delete this counter after 90 days.

You can add a photo of the vehicle registration certificate (Zulassungsbescheinigung Teil I) to your vehicle sale request. We do not need the registered keeper's surname, first name and address (fields C.1.1 to C.1.3) for the assessment and therefore make them illegible before anything is stored: immediately after the photo is taken, the app transmits it to our backend, which uses the text recognition service Amazon Textract (Frankfurt am Main region) to locate the printed field labels and covers these fields with a black bar. You see the result straight away in the app; only this blacked-out image is transmitted with your request and stored. The original photo and the recognised text are not stored, and Amazon Web Services does not use them to improve its services. If the registration certificate cannot be reliably recognised, the app discards the photo; you can take a new one or continue without the certificate. The check is only available with a confirmed customer account; to limit misuse, we count the checks per customer account and day (email address and number) and delete this counter after two days. The legal basis is Art. 6(1)(b) GDPR, and for the counter Art. 6(1)(f) GDPR (legitimate interest in protection against misuse).

The legal basis for the VIN scan is Art. 6(1)(b) GDPR (steps prior to entering into a contract, taken at your request), and for the counter Art. 6(1)(f) GDPR (legitimate interest in protection against misuse). What data your vehicle sale request itself contains, who processes it and when we delete it is described in the section “Vehicle sale request with photos”.

App push notifications

If you enable notifications in our app, your device generates a device identifier for push notifications (push token). We store this token together with the app language, the platform (iOS or Android) and the time of registration — without linking it to your customer account. We send the notifications via the push service of Expo (650 Industries, Inc., USA), which forwards them to the Apple Push Notification service (Apple Inc.) or to Firebase Cloud Messaging (Google); in the process, the token and the content of the notification are transmitted, including to the USA.

The legal basis is your consent, given by enabling notifications (Art. 6(1)(a) GDPR, § 25(1) TDDDG). You can disable them at any time in the app or in your device settings; if you disable them in the app, we delete the token immediately. The app renews the token each time it is started; if the token is not renewed for 180 days, we delete it automatically. For transfers to the USA, we rely on the European Commission's adequacy decision on the EU-US Data Privacy Framework, insofar as the respective provider is certified, and otherwise on standard contractual clauses.

Deleting your customer account

You can delete your customer account at any time: in the app in the “Account” area, on the website in your customer account (in both cases confirmed with your password) or by sending an email to the address given above under “Controller”. The website and the app use the same customer account; deletion applies to both. On the “Delete account” page we describe all methods step by step.

Upon deletion, we remove your customer account and the data stored in it — in particular your shortlist, saved searches, reservations (the vehicle is released), vehicle sale submissions including photos, and your newsletter subscription — and end all active logins. Entries in our log database that contain your email address are pseudonymised; log lines already written expire after the period stated in the section “Hosting and server log files”. Data on orders and payments that we are required to retain under statutory retention obligations (§ 257 HGB, § 147 AO) is separated from your account and deleted once those periods have expired. Vehicle sale requests whose offer you have already accepted are kept for processing and deleted after the period stated in the section “Vehicle sale request with photos”.

We do not delete customer accounts automatically — not even if they are not used for a long time. Your customer account remains until you delete it yourself or ask us to delete it.

Vehicle sale request with photos

If you offer us a vehicle for purchase in the app, you transmit to us the vehicle identification number (VIN), the mileage, further details about the vehicle, your telephone number and photos of the vehicle; we take your name and email address from your customer account. You take the photos with the camera in the app, which guides you through the required views of the exterior and interior; the app does not access your device's photo library. Please make sure that no other people can be recognised in the photos. For the photo of the registration certificate, see the section “VIN scan and registration certificate in the app”. A vehicle sale request is only possible with a confirmed customer account.

We store the request and the photos in the AWS region Frankfurt am Main. We notify our sales team of its receipt by email; the request is processed by our purchasing team in our internal management system, which is likewise operated in Frankfurt am Main. You can see an offer from us in the app with your submission. As long as you are logged in to the app, the app checks your customer account for this from time to time in the background and alerts you to a new offer with a notification on your device.

The legal basis is Art. 6(1)(b) GDPR (steps prior to entering into a contract, taken at your request). You can delete a request whose offer you have not yet accepted in the app at any time; it then disappears from your customer account. Internally it remains marked as withdrawn so that our purchasing team can trace this, and it is deleted after the following period. If we do not purchase the vehicle, we delete the request together with the photos six months after the last change (for example your last entry, our last offer or the withdrawal). If we do purchase the vehicle, we keep it for the statutory retention periods (§ 257 HGB, § 147 AO) and delete it ten years after the end of the year in which the purchase was agreed. If you delete your customer account, we remove requests that have not been accepted, together with their photos, as part of the deletion.

Location, camera and stock watch in the app

Location: The app uses your location only with your permission and only while you are using it — there is no location tracking in the background. It needs your location for two functions: under “Locations” it shows the distance to our sites, and the site map guides you to the vehicle you are looking for on our premises; for this it also reads your device's compass direction. The calculation takes place exclusively on your device: your location is neither transmitted to us nor to third parties and is not stored. The legal basis for the access is your consent given via your device's permission prompt (§ 25(1) TDDDG). You can withdraw the permission at any time in your device settings; the other functions of the app remain available.

Camera: The app also uses the camera only with your permission — to scan the QR code on a vehicle on our premises (the code is evaluated on the device, after which the app opens the vehicle), for the VIN scan and the registration certificate, and for the photos of a vehicle sale request. Only the images described in the sections “VIN scan and registration certificate in the app” and “Vehicle sale request with photos” are transmitted. The app does not record sound and does not access your photo library.

Stock watch and price alert: If you enable these functions, the app retrieves our public vehicle stock in the background from time to time and compares it with your search profile on your device. Your search profile, price limits and the list of vehicles already reported remain on the device; apart from the technical log data (see “Hosting and server log files”), retrieving the stock contains no information about you. The app reports matches with a notification that it creates directly on the device, without a push service. The app synchronises your shortlist, saved searches, reservations and tyre shopping basket with our server only when you are logged in with your customer account (see “Customer account (“Mein Parkplatz”)”). The legal basis for these functions requested by you is Art. 6(1)(b) GDPR.

Customer enquiries and lead handling (CRM)

When you submit a vehicle enquiry — via our contact form, by telephone or through a vehicle marketplace (e.g. mobile.de, AutoScout24) — we process the data provided (name, contact details, your request, the vehicle concerned) in our customer management system in order to handle your enquiry and advise you (Art. 6(1)(b) GDPR; additionally Art. 6(1)(f) GDPR for internal organisation, such as consolidating multiple enquiries from the same person). Marketplace enquiries reach us by email and are transferred into our system automatically.

For incoming calls, our telephone system matches the caller's number against open cases so that the right contact person can look after you; no permanent data is stored for unknown numbers in the process.

Retention period: We store enquiries for as long as they are needed for advice and support within an existing or prospective customer relationship; at your request we delete or anonymise them (Art. 17 GDPR), unless statutory retention obligations prevent this. Data relating to purchases is kept for the retention periods required by commercial and tax law (§ 257 HGB, § 147 AO). Marketing contact by email or telephone only takes place with separate consent or within the limits permitted by law (§ 7 UWG).

For technical operation we use a contractually bound processor (Art. 28 GDPR); processing takes place on servers in the EU (Frankfurt am Main region).

Incoming enquiry emails are pre-sorted by an AI language model (Claude by Anthropic, used via Amazon Bedrock with processing within the EU), for example to distinguish customer enquiries from out-of-office notices. Outside our opening hours, the same model may draft an automatic acknowledgement containing matching vehicle information; it is labelled as automatically generated, and a member of our team will get back to you on the next working day. We delete the logs of these automatic replies after 90 days (Art. 6(1)(f) GDPR, legitimate interest in prompt and orderly handling).

Interest profile (only with your consent)

If you have given your consent via our banner, we record which vehicle detail pages you visit and how long you view them (Art. 6(1)(a) GDPR). Without an account this is done under a random device identifier; with an account, the profile is linked to your account. We use this data exclusively internally to advise you better when you make an enquiry — no disclosure to third parties, no advertising networks. Anonymous profiles are deleted automatically after 6 months, profiles linked to a customer account 12 months after their last update.

Independently of this, we keep anonymous statistics on how often a vehicle appears in the list overall, is viewed, saved, reserved or enquired about, and how often the image gallery, the finance calculator, the condition report download, the telephone number or the share function are used; in addition, search terms with their number of results and the origin of the visit (pure counts, without any identifier, without storing IP addresses, Art. 6(1)(f) GDPR) — none of this can be linked back to you personally. We collect the same anonymous counts in our app; a personal interest profile as described above is not created there.

You can change your consent here at any time with effect for the future:

Current status: not yet decided

Audience measurement with Google Analytics (only with your consent)

We only embed Google Analytics 4 if you have consented to the “statistics” category via our banner (provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Art. 6 (1) a GDPR). Before your consent no Google script is loaded and no connection to Google is established — your IP address does not reach Google either. After consent, Google collects for us which pages are opened, how long visitors stay, which source they come from, as well as approximate location and device details. Your IP address is truncated and not stored permanently. We only evaluate aggregated reports; advertising features (Google Signals, remarketing, data sharing with advertising services) are switched off.

For this Google sets the cookies _ga and _ga_<property identifier> with a lifetime of up to 24 months. How long Google keeps the collected data is set in the property (at most 14 months). Transfer to Google LLC in the USA cannot be ruled out; Google LLC is certified under the EU-US Data Privacy Framework, and the European Commission’s standard contractual clauses apply in addition (Art. 46 (2) c GDPR). Despite these safeguards, access by US authorities cannot be completely ruled out. You can withdraw your consent at any time with effect for the future; the cookies are then deleted and no further data is collected.

You can change your consent to audience measurement here at any time with effect for the future:

Current status: not yet decided

Your rights (data subject rights)

Where the statutory requirements are met, you have the following rights under Art. 15 to 20 GDPR:

  • Right of accessArt. 15 GDPR
  • Right to rectificationArt. 16 GDPR
  • Right to erasureArt. 17 GDPR
  • Right to restriction of processingArt. 18 GDPR
  • Right to data portabilityArt. 20 GDPR
  • Right to objectArt. 21 GDPR

In addition, under Art. 21(1) GDPR you have the right to object to processing based on Art. 6(1)(f) GDPR, as well as to processing for the purposes of direct marketing.

Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority about our processing of your personal data. (Art. 77 DSGVO)

Die Landesbeauftragte für den Datenschutz Niedersachsen
Prinzenstraße 5

30159 Hannover

poststelle@lfd.niedersachsen.de

Video surveillance at our locations

We operate video surveillance on the premises we use. It serves to exercise our domiciliary rights, to prevent criminal offences and to assert, exercise or defend legal claims. The legal basis is Art. 6(1)(f) GDPR; where special categories of personal data are processed, Art. 9(2)(f) GDPR.

The data is passed on to service providers commissioned by us who perform surveillance duties for our company. Where criminal offences are suspected, we may also pass the data to lawyers, insurance companies and law enforcement authorities. Otherwise the data is only passed on where there is a legal basis for doing so — in particular where the police or other security authorities require access in the course of averting danger. No processing outside the European Union takes place in connection with the video surveillance.

Recordings from the video surveillance are generally deleted after 72 hours. Longer storage may take place on a case-by-case basis where facts justify the assumption that recordings from a defined period show conduct to be prosecuted as a criminal offence or used to assert civil claims.

Version: 17.09.2026