Skip to main content

Processing of (personal) data by the entity in charge of the online application process

Processing of Personal Data by the Controller Responsible for the Online Application Procedure

We provide you with this privacy notice, which applies exclusively to data collected in the context of the online application procedure, to inform you about how we handle your personal data collected during the application process.

1. Controller under Data Protection Law:
Plancraft GmbH
Flora-Neumann-Straße 6
20357 Hamburg
Phone: +49 40 328902430
E-Mail: info@plancraft.de
Legal notice: https://plancraft.de/impressum

2. Contact details of the Data Protection Officer:
Kertos GmbH
Brienner Str. 41, 80333 Munich
Data Protection Officer: Dr. Kilian Schmidt
‍dsb@kertos.io
‍‍+49 151 525 797 93

When contacting the data protection officer, please specify the company your request relates to. Please do not include sensitive information, such as a copy of your ID, with your enquiry.

3. Personal Data Processed during the Application Process

Personal data means any information relating to an identified or identifiable natural person. This includes, for example, your name, address, phone number, date of birth, as well as details about your professional background. Information that can only be linked to your identity in combination with other data is also considered personal data.
Data which cannot be attributed to you as an individual is not regarded as personal data.

4. Legal Basis and Purpose of Processing Personal Data in Applications and the Application Procedure

If you apply via e-mail or our online form, we collect and process your personal data solely for the purpose of conducting the application process and making decisions regarding a potential employment as well as for carrying out pre-contractual measures (e.g. preparing the employment contract).
Processing is based on Article 6 (1)(b) GDPR (pre-contractual steps) and, if necessary, to safeguard legitimate interests pursuant to Article 6 (1)(f) GDPR (e.g. defending against legal claims). We use your data exclusively for these purposes and do not share it without your explicit consent.

In particular, the following data will be collected:

  • Name (first and last)

  • Gender

  • E-mail address

  • Phone number

  • LinkedIn profile (optional)

  • Place of residence

  • Possible starting date

  • Salary expectations

  • Current title (optional)

  • Current employer (optional)

  • Years of professional experience (optional)

  • Channel by which you became aware of us

Information on your previous use of technologies (in particular artificial intelligence) in a professional context and specific examples thereof

Information regarding your willingness to be regularly present at the designated location, if required for the position  (e.g., Hamburg, Vienna)

You may also upload relevant documents such as your CV, certificates or other documents, which may contain further personal data (e.g. date of birth, address).
Providing information marked as "optional" is voluntary. If you leave required fields incomplete, we may not be able to process your application.

Access to your data is restricted to authorized employees and individuals actively involved in the recruitment process. Your data is handled with strict confidentiality.

Your personal data is stored exclusively for the purpose of carrying out the application procedure and filling the specific vacant position for which you apply.
After completion of the application process, your personal data is generally retained for up to six months, to defend possible claims under the German General Equal Treatment Act (AGG) or other legal claims. Thereafter, we will delete or anonymize your data, unless further statutory retention obligations exist.

For a longer data retention period, such as inclusion in our talent pool, we obtain your explicit voluntary and informed consent separately. In this case, you will be specifically informed about the purpose, duration of storage, and your right to withdraw consent. Without such consent, we do not include you in our talent pool.

Data in the talent pool will be deleted after withdrawal of consent or after one year at the latest. For statistical evaluation, we use only anonymized data.

If you are hired, we will store the data collected during the application procedure at least for the duration of your employment, insofar as this is legally permitted and necessary.


5. Disclosure of Data to Third Parties
Your data transmitted in the course of the application is transferred via TLS encryption and stored in a database operated by our external service provider, Personio GmbH (Rundfunkplatz 4, 80335 Munich, Germany). Personio provides applicant management software and processes your data on our behalf, in accordance with Article 28 GDPR under a data processing agreement.

Personio may employ subcontractors for service delivery. We ensure all providers meet the GDPR requirements and guarantee an adequate data protection level.

For more information about data protection at Personio GmbH, please visit: https://www.personio.de/datenschutz/.

Transferring your data to a third country (outside the EU/EEA) generally does not occur. Should data be transmitted to a third country in exceptional cases, this is done only in full compliance with legal requirements (particularly Art. 44 ff. GDPR).

6. Data Security and Protective Measures
We implement appropriate technical and organizational measures to ensure the security and confidentiality of your personal data. These measures are designed to protect against unauthorized access, manipulation, loss, or misuse. Our security provisions are reviewed regularly and adapted to technological progress and industry standards.

Please note that, despite extensive protective measures, internet-based data transmission may entail security risks. Particularly with unencrypted communication (e.g. standard email), third parties may be able to read data. We have no control over external parties' behavior. We therefore recommend using encryption or other security measures when transmitting sensitive information electronically to minimize potential risks.

7. Retention Period and Erasure/Blocking of Data
Personal data is deleted or blocked once the purpose for its storage ceases to exist. Extended storage occurs only where required by Union or national legislation applicable to the controller. Data is also deleted or blocked as soon as any legal retention period expires, unless further retention is required for contract performance.

8. Rights of Data Subjects
Regarding your personal data, you have the following rights:

  1. Right to access (Art. 15 GDPR, § 34 BDSG): You may request information about whether and which personal data is processed by us, the purpose of processing, recipients or categories of recipients, and the duration of storage.

  2. Right to rectification (Art. 16 GDPR): You may request correction of inaccurate data or completion of incomplete personal data.

  3. Right to erasure (Art. 17 GDPR): You may request deletion of your personal data, particularly if it is no longer needed, you withdraw your consent, or data has been processed unlawfully.

  4. Right to restriction of processing (Art. 18 GDPR): You may request to restrict processing, for example if the data's accuracy is contested.

  5. Right to data portability (Art. 20 GDPR): You have the right to receive the personal data you have provided in a structured, commonly used, and machine-readable format or – where technically feasible – to have it transferred directly to another controller.

  6. Right to withdraw consent (Art. 7 para. 3 GDPR): You can withdraw consent at any time with effect for the future. Lawfulness of processing prior to withdrawal remains unaffected.


Right to object (Art. 21 GDPR): You may object to the processing of your personal data at any time for reasons arising from your particular situation, especially regarding direct marketing or related profiling.

Right to lodge a complaint with a supervisory authority (Art. 77 GDPR): You have the right to complain to a supervisory authority if you believe that the processing of your personal data infringes data protection regulations.

9. Final Provisions
We reserve the right to amend this privacy notice at any time, to ensure continued compliance with legal requirements or to reflect changes in the application process or similar circumstances. For any subsequent visit to this recruitment site or resubmission of your application, the latest privacy notice will apply.

In addition to this privacy notice, you may access our general privacy policy at https://plancraft.de/datenschutz.

Processing of (personal) data by the operator of the recruitment website

General information

This recruitment website is operated by Personio SE & Co. KG, which offers a human resource and candidate management software solution (https://www.personio.com/legal-notice/). Data transmitted as part of your application will be transferred using TLS encryption and stored in a database. The sole controller of this data within the meaning of article 24 of the GDPR is the enterprise carrying out this online application process. Personio’s role is limited to operating the software and this recruitment website and, in this context, being a processor under article 28 of the GDPR. In this case, the processing by Personio is based on an agreement for the processing of orders between the controller and Personio. In addition, Personio SE & Co. KG processes further data, some of which may be personal data, to provide its services, in particular for operating this recruitment website. We will refer to this in more detail below.

The controller

The controller under data protection law is:
Personio SE & Co. KG
Seidlstraße 3
80335 München
Tel.: +49 (89) 1250 1004
Entry in the commercial register
Commercial register entry number: HRA 115934
Registration Court: Amtsgericht München
Data Protection Officer contact: privacy@personio.com

Access logs (“server logs”)

Each access to this recruitment website automatically causes general protocol data, so-called server logs, to be collected. As a rule, this data is a pseudonym and thus does not allow for inferences about the identity of an individual. Without this data, it would, in some cases, be technically impossible to deliver or display the contents of the software. In addition, processing this data is absolutely necessary under security aspects, in particular for access, input, transfer, and storage control. Furthermore, this anonymous information can be used for statistical purposes and for optimizing services and technology. In addition, the log files can be checked and analyzed retrospectively when unlawful use of the software is suspected. The legal basis for this is §25 subsection 2 Sentence 2 TDDDG. Generally, data such as the domain name of the website, the web browser and web-browser version, the operating system, the IP address, as well as the timestamp of the access to the software is collected. The scope of this log process does not exceed the common log scope of any other site on the web. These access logs are stored for a period of up to 7 days. There is no right to object to this.

Error logs

So-called error logs are generated for the purpose of identifying and fixing bugs. This is absolutely necessary to ensure we can react as quickly as possible to possible problems with displaying and implementing content (legitimate interest). As a rule, this data is a pseudonym and thus does not allow for inferences about the identity of an individual. The legal basis for this is §25 subsection 2 Sentence 2 TDDDG. When an error message occurs, general data such as the domain name of the website, the web browser and web-browser version, the operating system, the IP address, as well as the timestamp upon occurrence of the respective error message and/or specification is collected. These error logs are stored for a period of up to 7 days. There is no right to object to this.

Use of cookies

So-called cookies are used on parts of this recruitment website. They are small text files which are stored on the device with which you access this recruitment website. As a general rule, cookies serve the purpose of ensuring secure access to a website (“absolutely necessary”), implementing certain functionalities such as standard-language settings (“functional”), improving the user experience or the performance of the website (“performance”), or placing targeted advertisements (“marketing”). On this recruitment website, we generally use only cookies that are absolutely necessary, functional or performance-related, in particular for implementing certain default settings such as language, for identifying the job advertising channel, or for analyzing the performance of a job advert via which a user accessed this recruitment website. The use of cookies is absolutely necessary for providing our services and thus for the performance of the contract (article 6 (1) b) of the GDPR). Period of storage: up to 1 month or until the end of the browser session Right to object: You can determine via your browser settings whether you allow or object to the use of cookies. Please note that deactivating cookies may result in limited or completely blocked functionalities of this recruitment website.

Rights of data subjects

If Personio SE & Co. KG as the controller processes personal data, you as the data subject have certain rights under Chapter III of the EU General Data Protection Regulation (GDPR), depending on the legal basis and the purpose of the processing, in particular the right of access (article 15 of the GDPR) and the rights to rectification (article 16 of the GDPR), erasure (article 17 of the GDPR), restriction of processing (article 18 of the GDPR), and data portability (article 20 of the GDPR), as well as the right to object (article 21 of the GDPR). If the personal data is processed with your consent, you have the right to withdraw this consent under article 7 III of the GDPR. To assert your rights as a data subject in relation to the data processed for the purpose of operating this recruitment website, please refer to Personio SE & Co. KG’s Data Protection Officer (see item B).

Concluding provisions

Personio reserves the right to adjust this data privacy statement at any point in time to ensure that it is in line with the current legal requirements at all times, or in order to accommodate changes in the services offered, for example when new services are introduced. In this case, the new data privacy statement applies to any later visit of this recruitment website or any later job application.