Privacy policy
As at September 2026
GIS House and Garden Internet Shop GmbH, Rathausstraße 4, 20095 Hamburg, Germany ("GIS", "we", "us") attaches great importance to protecting your personal data and handling the information you entrust to us responsibly. Your personal data (hereinafter referred to as "data") is processed exclusively in accordance with the applicable statutory provisions, in particular the EU General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).
This Privacy Policy explains the nature, scope and purpose of the processing of your personal data when you
- visit our website
- contact us by email or via the contact form
- sign up for our newsletter
- enter into a contract with us
- apply for a position with us
- visit our company pages on a social network
- use a video conferencing service
- register with us
- follow links to social networks on our website
- use payment services on our website
This Privacy Policy also contains information about recipients of personal data within the EEA and in third countries, the deletion of your personal data and retention periods, your rights as a data subject and automated decision-making.
1. Name and address of the controller (Art. 4 No. 7 GDPR)
The controller responsible for data protection is GIS House and Garden Internet Shop GmbH, Rathausstraße 4, 20095 Hamburg, Germany, email: datenschutz@hhis.group.
Joint controllership pursuant to Art. 26 GDPR
For certain processing operations within our online shops, we and Hamburg Internet Shops Group GmbH are joint controllers within the meaning of Art. 26 GDPR. For this purpose, we have entered into an agreement on the joint processing of personal data, the essential content of which is set out below.
The joint controllers are:
GIS House and Garden Internet Shop GmbH, Rathausstraße 4, 20095 Hamburg, Germany, email: datenschutz@hhis.group, hereinafter GIS,
Hamburg Internet Shops Group GmbH, Rathausstraße 4, 20095 Hamburg, Germany, email: datenschutz@hhis.group, hereinafter HISG
Subject matter and purposes of the joint processing
The joint controllership covers the processing of personal data for the following purposes: centralised management of customer and master data within the group of companies, group-wide marketing and newsletter activities, cross-company analysis of usage and order data, and operation of shared IT and shop infrastructure. In particular, master data, contact details, order and contract data, and usage and tracking data are processed.
Allocation of responsibilities (essential content of the agreement pursuant to Art. 26 para. 1 GDPR)
In the agreement, the parties have specified in particular which party fulfils which data protection obligations:
GIS is primarily responsible for operating the online shop at hello-oskar.com, processing contracts with customers and fulfilling the information obligations pursuant to Art. 13 and 14 GDPR towards shop users.
HISG is primarily responsible for the group-wide marketing infrastructure, the central customer data warehouse, shared IT platforms and analytics tools.
Each party must independently implement appropriate technical and organisational measures pursuant to Art. 32 GDPR, notify the other party immediately of any data protection incidents and coordinate notifications pursuant to Art. 33 and 34 GDPR.
Exercise of data subject rights / central contact point
Irrespective of the internal allocation of responsibilities, you may exercise your rights under Art. 15 to 22 GDPR against either joint controller in accordance with Art. 26 para. 3 GDPR. To process your requests as quickly as possible, we have established the following central contact point:
HISG: email: datenschutz@hhis.group
We will be pleased to provide you with a complete summary of the agreement pursuant to Art. 26 GDPR upon request.
2. Contact details of the Data Protection Officer
If you have any questions about this Privacy Policy or data protection at HISG, or if you wish to exercise your rights as a data subject, you can contact our Data Protection Officer at datenschutz@hhis.group.
3. Data protection principles for the processing of your personal data
The purpose and legal basis of our data processing depend on which of our services you use. This is explained in the following sections.
We use external service providers for certain functions of our offering and to conduct our business operations (e.g. in the areas of IT, logistics, telecommunications, sales and marketing). We always select these service providers carefully; they are bound by our instructions and are regularly monitored. The service providers we use are contractually obliged to process data properly in accordance with Art. 28 GDPR. In the following sections, we inform you about the respective processing activities. Unless otherwise stated in this Privacy Policy, we do not generally transmit your data to third parties. In exceptional cases, data will be disclosed if we are obliged to do so under statutory provisions and/or official or court orders.
4. General use of the website
When you visit our website, we process the internet connection data that your browser automatically transmits to our server. This data includes your IP address and other usage data (e.g. the date and time of access, the name of the page accessed, the amount of data transferred and the requesting provider). We require this data for technical reasons to provide you with our website and to ensure its stability and security, and must therefore process it.
This data may constitute personal data. The legal basis for this data processing is our legitimate interest in ensuring the security and usability of our website, Art. 6(1)(f) GDPR.
5. Cookies and similar technologies
Our website (https://hello-oskar.com) uses tracking technologies that enable us or our contractual partners or service providers to collect data relating to the use of our websites. These tracking technologies are commonly referred to as cookies, which is why we use this term below. However, the following information also applies accordingly to other tracking technologies or file formats, such as Local Storage, pixels, beacons or tags.
Cookies are text files placed and stored on a computer system via an internet browser. When you visit our website again, the cookie ID (the cookie's unique identifier) is transmitted to our web server. The cookie ID enables us, for example, to recognise you and take individual settings into account when displaying the website. Some of these cookies are strictly necessary to ensure the technical functionality of the website. In these cases, access to your terminal device is based on Section 25(2)(2) TDDDG. Where this information relates to an identifiable person and is further processed by us in our IT systems, the legal basis for this data processing is our legitimate interest in providing our website and ensuring data security, Art. 6(1)(f) GDPR.
We only use other cookies that are not strictly necessary for technical purposes ("cookies requiring consent") with your consent. We use the following categories of cookies requiring consent:
- Performance cookies: These cookies allow us to count visits and traffic sources so that we can measure and improve the performance of our website. They help us determine which pages are the most popular, which are used the least and how visitors move around the website. All information collected by these cookies is aggregated and therefore anonymous. If you do not allow these cookies, we cannot know when you visited our website.
- Functional cookies: These cookies enable our website to provide enhanced functionality and personalisation. They may be set by us or by third-party providers whose services we use on our pages. If you do not allow these cookies, some or all of these services may not function.
- Marketing cookies: These cookies may be set on our website by our advertising partners. These companies may use them to create a profile of your interests and show you relevant advertisements on other websites. They do not directly store personal data but are based on the unique identification of your browser and internet device. If you do not allow these cookies, you will receive less targeted advertising.
When our website is accessed, we inform the website visitor about the use of cookies requiring consent by displaying an appropriate banner and obtain their consent to the processing of the personal data used in this context. By making the relevant selection in the cookie banner, you consent both to the storage and retrieval of information in these cookies requiring consent via our website in accordance with Section 25(1) TDDDG and to the further processing of any personal data retrieved in accordance with Art. 6(1)(a) GDPR. Cookies requiring consent are only set after you have given your consent. Before you give your consent, only technically necessary cookies are set.
In addition to our cookie banner, you may restrict your consent to the setting of cookies, either wholly or partly, by configuring your browser settings accordingly and disabling the setting of cookies, either wholly or partly. You may also install a privacy plugin in your browser that prevents web analytics, such as AdBlock, Ghostery or NoScript (please refer to the privacy information provided by the respective plugin provider). Some web analytics providers are also members of industry associations whose websites allow you to centrally prevent interest-based online advertising and web analytics by the respective members. The websites of these associations are listed below, allowing you to conveniently prevent web analytics across different providers and thus also prevent the creation of pseudonymous usage profiles.
- "European Interactive Digital Advertising Alliance" (EDAA): http://www.youronlinechoices.com/de/praferenzmanagement/
- "Digital Advertising Alliance" (DAA): www.aboutads.info/choices
- "Network Advertising Initiative" (NAI): http://optout.networkadvertising.org/?c=1
Alternatively, you may withdraw your consent at any time with effect for the future (Art. 7(3) GDPR) by clicking the "Cookie settings" button and disabling the relevant cookies.
If you do not give your consent to the use of cookies or delete cookies from your terminal device, this may affect your ability to use the website or individual features.
6. Google Analytics
This website uses Google Analytics, a web analytics service provided by Google LLC., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (‘Google’), if you have given us your consent via the cookie banner (Art. 6(1)(a) GDPR). Google Analytics uses cookies to analyse your use of the website. The information generated by the cookie about your use of this website is generally transmitted to and stored on a Google server in the USA. However, Google first truncates and thereby anonymises your IP address within Member States of the European Union or other states that are party to the Agreement on the European Economic Area. Only in exceptional cases is the full IP address transmitted to a Google server in the USA and truncated there. On behalf of the controller of this website, Google will use this information to evaluate your use of the website, compile reports on website activity and provide the website operator with other services relating to website and internet use. The IP address transmitted by your browser as part of Google Analytics will not be combined with other Google data.
Google LLC is certified under the EU-U.S. Data Privacy Framework.
You can view Google’s privacy policy at the following link: http://www.google.com/intl/de/policies/privacy/
7. Google Tag Manager
We use Google Tag Manager. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Tag Manager is a tool that enables us to integrate tracking or statistical tools and other technologies into our website. Google Tag Manager itself does not create user profiles, store cookies or carry out any independent analyses. It is used solely to manage and deploy the tools integrated through it. However, Google Tag Manager collects your IP address, which may also be transmitted to Google’s parent company in the United States (Google LLC, 1600 Amphitheater Parkway, Mountain View, CA 94043, USA). This parent company is certified under the EU-U.S. Data Privacy Framework, ensuring an adequate level of protection for this data transfer. We have also concluded a data processing agreement with Google. Google Tag Manager is used on the basis of Art. 6(1)(f) GDPR. The website operator has a legitimate interest in the quick and straightforward integration and management of various tools on its website. Where consent to the use of certain tools has been requested and given, the associated processing is carried out exclusively on the basis of Art. 6(1)(a) GDPR and also Section 25(1) TDDDG, where the consent covers the storage of cookies or access to information on the user’s terminal device within the meaning of the TDDDG. Consent may be withdrawn at any time; for information on withdrawal, see the ‘Cookies & Web Analytics’ section.
8. Google reCAPTCHA
To protect the enquiries you submit via the contact form, we use the reCAPTCHA service provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (‘Google’). The verification process distinguishes whether the input is made by a human or is being misused through automated machine processing. This process includes sending the IP address and, where applicable, other data required by Google for the reCAPTCHA service to Google. For this purpose, your input is transmitted to Google and used there. However, Google first truncates your IP address within Member States of the European Union or other states that are party to the Agreement on the European Economic Area. Only in exceptional cases is the full IP address transmitted to a Google server in the USA and truncated there.
On behalf of the operator of this website, Google will use this information to evaluate your use of this service. The IP address transmitted by your browser as part of reCAPTCHA will not be combined with other Google data. This data is subject to Google’s separate privacy policy.
Google LLC is certified under the EU-U.S. Data Privacy Framework.
9. Categories of Recipients
As part of our business activities, we use external service providers to whom personal data may be transmitted. Below, we provide information about the categories of these recipients, the respective purpose of the data processing, the legal basis and the level of protection for any transfers to third countries. We will be pleased to provide you with the specific list of providers used upon request.
9.1. Shop Platform & IT Infrastructure
Our online shop is operated on an external e-commerce platform provided by a company based in Canada. As part of the shop’s operation, this provider processes customer and order data (in particular names, addresses, email addresses, payment history and order history) on our behalf. An adequacy decision by the European Commission applies to data transfers to Canada. The legal basis is Art. 6(1)(b) GDPR (performance of a contract). A data processing agreement is in place pursuant to Art. 28 GDPR.
9.2. Cloud Infrastructure & Hosting
We use cloud hosting services provided by companies based in the European Union (Luxembourg and Ireland) to operate our IT infrastructure. Data is processed on servers within the European Union. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in the secure and reliable operation of our services). Data processing agreements pursuant to Art. 28 GDPR are in place with the providers.
9.3. Payment Service Providers
We work with several payment service providers to process payments. Depending on the payment method you select, your payment and order data will be transmitted to the relevant service provider. The providers used are companies based in the European Union (Germany, Luxembourg, Ireland and Sweden), as well as one provider based in Canada, for which an adequacy decision by the European Commission is in place. The payment service providers may carry out their own risk assessments for fraud prevention and credit checks. The legal bases are Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(f) GDPR (fraud prevention).
9.4. Shipping Providers & Logistics
To dispatch orders, we transmit the necessary recipient data (name, delivery address and, where applicable, email address and telephone number for shipping notifications) to external parcel delivery and logistics providers based in Germany. The data is transmitted solely for the performance of the purchase contract and is limited to the minimum necessary for this purpose. The legal basis is Art. 6(1)(b) GDPR (performance of a contract).
9.5. Email & SMS Marketing
We use an external marketing automation platform provided by a company based in the USA to send marketing communications (newsletters, SMS) and transactional messages (e.g. order confirmations and shipping notifications). The provider is certified under the EU-U.S. Data Privacy Framework, ensuring an adequate level of protection for data transfers to the USA. Marketing emails are sent exclusively on the basis of your consent (Art. 6(1)(a) GDPR); transactional messages are sent on the basis of performance of a contract (Art. 6(1)(b) GDPR). A data processing agreement pursuant to Art. 28 GDPR is in place.
9.6. Review Platforms
We work with external review platforms to collect and publish customer reviews. After an order has been completed, we transmit the purchasers’ names and email addresses to the relevant provider for this purpose so that an invitation to submit a review can be sent. The providers used are companies based in the European Union (Denmark) and the United Kingdom; an adequacy decision by the European Commission is in place for the United Kingdom. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in presenting customer feedback transparently).
9.7. Web Analytics & User Feedback
If you have given your consent via our cookie banner, we use a web analytics service provided by a company based in the European Union (Malta) to analyse user behaviour on our website using heatmaps, session recordings and surveys and to improve the user experience. Pseudonymised usage data, such as mouse movements, clicks and scrolling behaviour, is collected in the process. The legal basis is Art. 6(1)(a) GDPR (consent). Data is processed on servers within the European Union.
9.8. Marketing Analytics & Attribution
We use marketing analytics software provided by a company based in Germany to evaluate our marketing campaigns and optimise our marketing mix based on data. Aggregated data on advertising expenditure and revenue trends is processed for this purpose. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in optimising our marketing activities). Data is processed on servers within Germany.
9.9. Cookie Consent Management
We use a consent management platform to fulfil our information and consent obligations under the GDPR and the ePrivacy Directive. You can give or refuse consent via the cookie banner embedded on our website; your settings are logged and stored. The providers used are companies based in Germany and the European Union (Bulgaria), respectively. The legal basis is Art. 6(1)(c) GDPR (compliance with legal obligations).
9.10. AI Language Models & Chatbot
We use AI-powered services (language models and chatbot technology) to support internal processes, create content and respond to customer enquiries automatically. The providers used are companies based in Ireland and Germany, respectively. Appropriate safeguards for transfers to third countries pursuant to Art. 46 GDPR are in place for providers whose parent companies are based in the USA. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in optimising internal processes and customer service). Data processing agreements pursuant to Art. 28 GDPR are in place.
9.11. Customer support software
We use external helpdesk software from a provider based in the USA to process customer enquiries and support tickets. The provider is certified under the EU-U.S. Data Privacy Framework, ensuring an adequate level of protection for data transfers to the USA. When you contact us, your enquiries and the personal data submitted with them (in particular your name, email address and message content) are stored and processed on our behalf by the service provider. The legal bases are Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(f) GDPR (legitimate interest in efficient customer service). A data processing agreement is in place pursuant to Art. 28 GDPR.
9.12. ERP software
We use ERP software from a provider based in Germany to manage our business processes (order management, stock management, accounting and shipping). Customer and order data are processed in this context. The legal bases are Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(f) GDPR (legitimate interest in efficient business management). The data are processed on servers located within Germany. A data processing agreement is in place pursuant to Art. 28 GDPR.
9.13. Internal collaboration & communication tools
We use various software services for internal collaboration, project management and corporate communications. The providers are based in the USA, Israel and Australia. The providers used in the USA are certified under the EU-U.S. Data Privacy Framework, or other appropriate safeguards are in place pursuant to Art. 46 GDPR. Adequacy decisions by the European Commission are in place for Israel and Australia. These services process employee data and internal project data only; no customer data are transferred. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in efficient internal collaboration). Data processing agreements are in place pursuant to Art. 28 GDPR.
9.14. HR software
We use external HR software from a provider based in Germany to manage personnel files, payroll, holiday requests and recruitment processes. Only employee data are processed in connection with this use. The legal bases are Art. 6(1)(b) GDPR (performance of contracts with employees) and Art. 6(1)(c) GDPR (compliance with legal obligations). The data are processed on servers located within the European Union. A data processing agreement is in place pursuant to Art. 28 GDPR.
9.15. Fulfilment service provider
We use an external fulfilment service provider based in Germany to store our products, pick and pack orders, and hand them over to shipping service providers. As part of this cooperation, we transfer order data (in particular the recipient’s name, delivery address, ordered items and quantities) to the service provider so that it can fulfil the orders on our behalf. The processing is based on the performance of a contract (Art. 6(1)(b) GDPR). The data are processed exclusively on servers and in warehouses located within Germany. A data processing agreement is in place pursuant to Art. 28 GDPR.
Information about specific service providers
Pursuant to Art. 15 GDPR, you have the right to obtain information about the specific service providers we use. We will be pleased to provide you with a complete list of our processors and third-party recipients upon request. Please send your request to: datenschutz@hhis.group.
10. Registration on our website
You may register on our website by providing your personal data. The personal data transmitted to us are determined by the relevant registration form. The personal data you enter are collected and stored internally by us exclusively for our own purposes.
When you register on our website, your IP address and the date and time of registration are also stored. These data are stored for security reasons and to prevent misuse of our services. Where necessary, they may also be used to investigate criminal offences. We therefore need to store these data in our capacity as controller. As a rule, we do not disclose these data to third parties unless there is a legal obligation to do so or disclosure is required for law enforcement purposes.
Registering and voluntarily providing personal data enables us to offer you content or services that are available only to registered users. You may change the personal data you have provided or have them deleted entirely from our system at any time.
You can access your customer account without a password using a time-limited login code that we send to your email address. The legal basis is Art. 6(1)(b) GDPR; we process the technical data required to secure the account on the basis of our legitimate interest pursuant to Art. 6(1)(f) GDPR.
11. Contact via the contact form or other communication channels
When you contact us via our contact form, we store the data you provide (email address, name and telephone number where applicable, and the content of your message) in order to answer your questions and deal with your enquiry. We use this information to clarify your enquiry and deal with your request more effectively. You provide this information expressly on a voluntary basis. Your personal data will only be disclosed to third parties if this is necessary to answer your enquiry. The legal basis is either the performance of a contractual obligation, steps taken prior to entering into a contract, or our legitimate interest in providing a contact form (Article 6(1)(b) and (f) GDPR). You are under no obligation to contact us via the contact form or by email, nor to provide personal data. If you do not provide your personal data, we may be unable to deal with your enquiry. Otherwise, there will be no consequences for you. We process your data in the same manner if you contact us with an enquiry by post, email or telephone.
12. Links to social networks
Our website contains links to social networks. These services are operated exclusively by third-party providers. If you follow these links, information, particularly your IP address and other device information, may be transmitted to these providers. We use what is known as the "two-click solution" for links to social networks. This means that, as a general rule, no personal data is disclosed when you visit our website. Data is transmitted to the relevant provider only when you click one of the social sharing buttons. For information about the purpose and scope of data collection, the provider's further processing and use of the data, as well as your related rights and the settings available to protect your privacy, please refer to the respective provider's privacy policy:
- Facebook: Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland; parent company: Facebook Inc., 1 Willow Road, Menlo Park, CA 94025, USA; website https://www.facebook.com; privacy policy: https://de-de.facebook.com/about/privacy/update; option to object (opt-out): advertising settings at https://www.facebook.com/settings?tab=ads.
- Instagram: Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland; parent company: Facebook Inc., 1 Willow Road, Menlo Park, CA 94025, USA; website https://www.instagram.com; privacy policy: https://instagram.com/about/legal/privacy.
- YouTube: the service provider is Google Ireland Limited, Gordon House, Barrow St, Dublin 4, Ireland; parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, California, USA; website: https://www.youtube.com/; privacy policy: https://policies.google.com/privacy?hl=de
- LinkedIn: the service provider is LinkedIn Ireland Unlimited Company Wilton Place, Dublin 2, Ireland; parent company: LinkedIn Corporation, 1000 W Maude Ave, Sunnyvale, CA 94085, USA; website: https://www.linkedin.com/; privacy policy: https://de.linkedin.com/legal/privacy-policy
- Xing: the service provider is New Work SE, Am Strandkai 1, 20457 Hamburg, Germany; website: https://www.xing.com/; privacy policy: https://privacy.xing.com/de/datenschutzerklaerung
13. Joint controllership with operators of social networks
GIS maintains social media presences on various social networks. As the operator of these pages, we and the respective operator of the social network are joint controllers within the meaning of the General Data Protection Regulation (GDPR) for the collection (but not the further processing) of data from visitors to our company page. On our social media presences, we publish and share content, offers and product recommendations. Whenever you interact with our presences, the operators of the social media services use cookies and similar technologies to record your usage behaviour. The operators can view general statistics on the interests and demographic characteristics of the audience. When you use social networks, the nature, scope and purposes of data processing on social networks are primarily determined by the operators of the social networks.
We have presences on the following social networks:
- Facebook: Facebook Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland
- Instagram: Facebook Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland
- YouTube: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
- LinkedIn: LinkedIn Ireland Unlimited Company Wilton Place, Dublin 2, Ireland
- Xing: New Work SE, Am Strandkai 1, 20457 Hamburg, Germany
We have entered into a specific agreement with the respective operator of the social network which stipulates, in particular, the security measures that the operator must observe and under which the operator has agreed to fulfil the rights of data subjects (i.e. users can, for example, submit requests for information or erasure directly to the operator of the social network).
The rights of visitors (in particular to access, erasure, objection and lodging a complaint with the supervisory authority) are not restricted by the agreements with the respective operator. You may exercise your rights (access, rectification, erasure, restriction of processing, data portability, objection and complaint) both against us and against the respective operator of the social network.
14. Conclusion and performance of contracts, steps prior to entering into a contract
We would like to inform you that the provision of personal data is sometimes required by law (e.g. under tax regulations) or may arise from contractual provisions (e.g. information about the contracting party). It may occasionally be necessary for the conclusion of a contract that you provide us with personal data which we must then process. For example, if our company enters into a contract with you, you are obliged to provide us with the necessary personal data. Failure to provide this data would mean that the contract with you could not be concluded.
15. Configurator, quotation requests and advice
If you use the chimney configurator or request a quotation, we process your configuration data, contact details, information entered in free-text fields and, where applicable, address details to provide advice, prepare and follow up the quotation and take steps prior to entering into a contract in accordance with Art. 6(1)(b) GDPR. For processing purposes, the data may be stored in our shop, merchandise management, customer service and CRM systems and transferred to the employees and service providers handling the request.
We will contact you via WhatsApp only if you provide separate, voluntary consent for this purpose. We will then store the consent together with the time it was given and its relation to the request. The legal basis is Art. 6(1)(a) GDPR. You may withdraw your consent at any time with effect for the future; your request can still be processed without WhatsApp.
16. Transfer of existing customer data from the previous OSKAR shop
As part of the system change from Magento to Shopify, existing customer master data and the information required for ongoing contractual, service, warranty or record-keeping obligations may be transferred to the new systems. Existing passwords will not be transferred; historical orders will generally remain in the previous archive system. The legal bases are Art. 6(1)(b) and (c) GDPR and our legitimate interest in secure and continuous customer support and system migration in accordance with Art. 6(1)(f) GDPR.
17. Data protection for applications and during the recruitment process
We collect and process applicants’ personal data for the purpose of managing the recruitment process. This may also take place electronically, particularly if applicants submit their documents by email, via a web form or, where applicable, through our careers portal.
As a rule, we process your name, address, email address, telephone number, marital status, qualifications, any other personal information contained in your cover letter and CV, as well as any file attachments you may include (including your CV and references). This processing is carried out for the purpose of contacting you and assessing your suitability for the position for which you are applying. The legal basis is Section 26(1), (8), sentence 2 BDSG or Section 26(2), (8), sentence 2 BDSG. If we enter into an employment contract with an applicant, the data submitted will be stored in accordance with statutory provisions for the purpose of managing the employment relationship.
If no employment contract is entered into, the application documents will be automatically deleted six months after notification of the rejection decision, unless the controller has other legitimate interests in retaining them. Such a legitimate interest could, for example, be the obligation to provide evidence in proceedings under the German General Equal Treatment Act (AGG).
18. Subscription to our newsletter
On our website, we offer visitors the opportunity to subscribe to our newsletter. The personal data transmitted to us for processing when subscribing to the newsletter is specified in the relevant input form.
We regularly inform customers and business partners about our offers by newsletter. To receive the newsletter, the person concerned must have a valid email address and register to receive it. For legal reasons, a confirmation email is sent through the double opt-in process to the email address entered for the first time in order to verify authorisation to receive the newsletter.
When you subscribe to the newsletter, we also store the IP address of the computer system used and the date and time of registration. This data is collected to prevent possible misuse of the email address and serves to provide legal protection for the controller.
The personal data collected is used exclusively for sending the newsletter. Subscribers may also be informed by email about changes to the newsletter service or technical circumstances. The newsletter subscription may be cancelled at any time, and consent to the storage of data may be withdrawn either via the relevant link in each newsletter or by contacting us directly.
19. Payment services
We integrate payment services provided by third-party companies into our website. If you make a purchase from us, your payment data (e.g. name, payment amount, bank details and credit card number) will be processed by the payment service provider for the purpose of processing the payment. The respective contractual and data protection provisions of the relevant providers apply to this transaction. The payment service providers are used on the basis of Art. 6(1)(b) GDPR (contract performance) and in the interest of ensuring that the payment process is as smooth, convenient and secure as possible (Art. 6(1)(f) GDPR). Where your consent is requested for certain actions, Art. 6(1)(a) GDPR is the legal basis for data processing; consent may be withdrawn at any time with effect for the future. Where the payment services place cookies, the legal basis is likewise your consent pursuant to Art. 6(1)(a) GDPR.
20. Data processing when using a video conferencing service
Where applicable, we use a third-party video conferencing service for telephone calls and online meetings with you. If you participate in such meetings, information may be transmitted to the relevant provider. Your participation in such a meeting is voluntary. If required, we will be happy to provide you with another means of communicating with us.
The legal basis for processing your personal data in connection with online meetings is Art. 6(1)(b) GDPR (if we hold the meeting to perform a contractual relationship with you) or Art. 6(1)(f) GDPR (if we hold the meeting for other business purposes); in the latter case, our legitimate interest lies in being able to use functional and widely used video conferencing tools in order to communicate efficiently with third parties (e.g. applicants, employees of external service providers or partners).
We do not record video conferences or telephone conferences. Video conferences are secured in accordance with the state of the art and are end-to-end encrypted where the third-party provider technically offers this in the specific circumstances.
21. Transfer of data to third parties and countries outside the European Economic Area (EEA)
We place importance on processing your data within the European Union (EU)/European Economic Area (EEA). Except for the processing activities described in this Privacy Policy, we do not transfer your data to recipients based outside the EU or EEA. If the level of data protection there does not correspond to the level of data protection within the EU, or if the recipient does not fall within the scope of an adequacy decision by the European Commission, we ensure that the requirements of Chapter V of the GDPR are met and that an adequate level of data protection is therefore guaranteed at the recipient. Most of the US providers we use are certified under the EU-U.S. Data Privacy Framework, enabling data to be transferred securely to these US providers. A complete list of companies certified under the EU-U.S. Data Privacy Framework is available at the following link: https://www.dataprivacyframework.gov/s/participant-search. If a provider is not certified under the EU-U.S. Data Privacy Framework, it is contractually bound by the EU Standard Contractual Clauses to process data in compliance with data protection law. Please note that stricter rules generally apply to government surveillance programmes in the USA; these were adopted as a prerequisite for the European Commission's adequacy decision. These stricter requirements governing access to data through surveillance programmes operated by US intelligence services must also be taken into account when transferring data to non-certified US companies and will generally mean that the transfer of data is permissible under the GDPR.
If, in exceptional cases, this is not possible, we will also obtain your consent to such a transfer of data to a third country through our cookie banner (Art. 49(1)(a) GDPR).
22. Retention and deletion of your data
GIS deletes your personal data
- as soon as processing is no longer necessary for the purposes explained in this Privacy Policy;
- if you object under Art. 21(1) GDPR and no compelling legitimate grounds of GIS and HISG preclude deletion
- or, if consent is withdrawn, there is no other legal basis for processing.
In certain cases, for example where a statutory retention period applies, your personal data will initially be blocked and deleted once the retention period has expired. In particular, retention periods under commercial and tax law must be observed (up to 10 years), and it may be necessary to store personal data to defend against legal claims (up to 30 years).
In cases permitted by law, we may refrain from deletion where the data is anonymous or pseudonymised and deletion would make processing for scientific research or statistical purposes impossible or would impair such processing.
23. Data security
We have implemented the necessary technical and organisational measures to protect your data against accidental or deliberate manipulation, loss, destruction or access by unauthorised persons. Our employees and all persons involved in data processing are required to comply with applicable data protection laws and to handle personal data confidentially. Our employees receive appropriate training.
Our security procedures are reviewed regularly and adapted in line with technological advances. To protect our users' personal data, we use a secure online transmission method known as "Secure Socket Layer" (SSL) transmission. You can recognise this by the "s" added to the http:// part of the address ("https://") or by a green, closed padlock symbol displayed in the browser. Clicking the symbol provides information about the SSL certificate used. SSL encryption ensures the secure and complete transmission of your data.
24. Your rights as a data subject (data subject rights)
Subject to the respective statutory requirements, you have the following rights (known as data subject rights) regarding the personal data relating to you:
- Right to obtain confirmation as to whether we process your personal data (Art. 15 GDPR),
- Right of access to your personal data processed by us and to receive a copy of the data (Art. 15 GDPR),
- Right to rectification if your personal data is inaccurate (Art. 16 GDPR),
- Right to erasure of your personal data (Art. 17 GDPR),
- Right to restriction (blocking) of your personal data (Article 18 GDPR),
- Right to data portability (Art. 20 GDPR),
- Right to withdraw any consent given (Art. 6(1)(a) GDPR) with effect for the future (Art. 7(3) GDPR). Please note that, if you withdraw your consent, we will continue to retain a record of it. This is because, even after consent has been withdrawn and your personal data has been erased, we must be able to demonstrate that consent was given. The legal bases for the retention (including continued retention) of the consent are Art. 6(1)(c) in conjunction with Art. 5(1)(a), (2), Art. 7(1) GDPR and Art. 6(1)(f) GDPR,
- Right to object (Art. 21 GDPR): Where our processing of data is based on a legitimate interest pursuant to Art. 6(1)(f) GDPR, you have the right to object. This means that you may object to our processing of your personal data at any time on grounds relating to your particular situation. Following your objection, we will no longer process your personal data unless there are demonstrably compelling legitimate grounds for the processing that override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims. Where we process personal data for direct marketing purposes, you may object to this at any time pursuant to Art. 21(2) GDPR. In this case, we will no longer process your data for this purpose.
You also have the right to lodge a complaint with the competent data protection supervisory authority (see Art. 77 GDPR).
If you wish to exercise your data protection rights, you can contact our Data Protection Officer at datenschutz@hhis.group. Further information can be found in Section 2.
25. Automated individual decision-making
We do not make decisions based solely on automated processing of your data that produce legal effects concerning you or similarly significantly affect you (Art. 22 GDPR).
26. Amendments and updates to this Privacy Policy
New legal requirements, business decisions or technological developments may require amendments to our Privacy Policy. The Privacy Policy will then be amended accordingly. You can always find the current version on our website.
Last updated: 27 August 2026 · SHA-256: 08069de29970b255e42b795a2b584c3a1fff093d5d30d23fd51ede0ed8d4aff6