Privacy Policy

Privacy policy of OneCinema GmbH

1. Preamble

We are pleased about your visit on the website of our company. Information protection and in particular data protection is of great importance to our management. In principle, you can use this website without providing any personal data. Should you disclose data to us in connection with the processing described below, we will treat your personal data confidentially and in accordance with the legal data protection regulations of the European Union and the Federal Republic of Germany as well as this data protection declaration.

As the data controller, OneCinema GmbH has implemented numerous technical and organizational measures to ensure the complete protection of personal data processed via this website. However, Internet-based data transmissions can generally have security gaps, so that absolute protection cannot be guaranteed. For this reason, you as the person concerned are free to transmit personal data to us by alternative means, for example by telephone or mail.

2. Definitions

OneCinema GmbH's data protection declaration is based on the terms used by the European legislator when the basic data protection regulation (GDPR) was issued. The detailed definitions can be found in Art. 4 GDPR. Essentially, these are the following terms, described here in simplified form:

a) Personal data:

This is all information available to us as a responsible person to determine you as a natural person. (e.g. name, address, e-mail, telephone number, IP address etc.)

b) Person concerned:

This is you as a natural person, if we have identified you or can identify you.

c) Processing:

Processing is any collection, storage, further processing, forwarding, archiving and deletion of data. It is irrelevant whether the process is carried out automatically with the aid of IT systems or whether it is carried out manually (e.g. by letter).

d) Restriction of processing:

Restriction of processing is the marking of stored personal data with the aim of restricting their future processing.

e) Profiling:

Profiling is any type of automated processing of your data, which consists in using these data to evaluate certain personal aspects relating to you. In particular, to analyse or predict aspects relating to your job performance, economic situation, health, personal preferences, interests, behaviour, whereabouts or change of location.

f) Pseudonymization:

This is a process to identify your personal data. In the following, only this identifier will be used and without the original key or a "reference database" this pseudonym cannot be resolved (e.g. allocation of a customer number).

g) Responsible Person:

The person responsible or responsible for processing is OneCinema GmbH with whom you have a contractual relationship. It is crucial that we can decide independently on the processing methods and means.

h) Contract processor:

A processor is a company that has been commissioned by OneCinema GmbH to assist you in the collection, processing, storage, forwarding or deletion of your data. Usually these are IT service providers, but also waste disposal companies that are commissioned, for example, with the destruction of documents.

i) Consent:

Consent is any expression of will given by you for a specific individual case. You will be fully informed about what you are consenting to.

3. The name and address of the controller

The person responsible for this website and the central services of OneCinema GmbH within the meaning of the Data Protection Basic Regulation and other regulations of a data protection nature is:

OneCinema GmbH
Industriestrasse 6b
97359 Schwarzach am Main
Germany

Managing Director:
Joachim Schmitt

Phone: +49 9324 88 99 80 0
Email: contact@onecinema.de

4. Data Protection Officer

A data protection officer has been appointed for OneCinema GmbH. He is available at any time to answer your questions in connection with data processing.

Data Protection Officer – Confidential –

Am Alten Bahnhof 8
D-97332 Volkach

Phone: 09381 / 71 77 8 - 59
Mail: eicin.datenschutz@eikona.de

5. Rights of the data subject

In accordance with Chapter 3 of the GDPR, you have the following rights as a data subject. In order to fulfil our obligations in connection with your rights in accordance with the law, please address appropriate inquiries to our data protection officer.

a) Art. 15 Right to information

You have an unlimited right to request information about the personal data processed by you. This information must be provided to you free of charge. You may request information on the following information, a copy of which must also be sent to you

  • the purpose of processing your data,
  • the categories of data,
  • the internal and external recipients of your data,
  • the duration of data storage,
  • their rights under Chapter 3, in connection with data processing,
  • the origin of the data if it was not collected from you,
  • whether a profile has been created,
  • whether your data has been transferred to a third country (non-EU and non-EEA),
  • which data protection authority is responsible for our respective company

b) Art. 16 Right of rectification

Should we process incorrect data from you, you can have this corrected at any time by your contact person.

c) Art. 17 Right of cancellation

You have the right to request the deletion of your personal data at any time. We may be required by law to retain your data for a certain period of time (e.g. 6 years for business mail or 10 years for tax-related documents). In such a case we will block your data record until the retention period has expired and then delete the data record accordingly. Please address deletion requests to the data protection officer, who will exercise your rights in our company on your behalf.

d) Art. 18 Right to limit processing

If you dispute the accuracy of our personal data, or if you refuse to have your data deleted and instead demand the restriction (e.g. in the case of advertising mail), you can demand the restriction of processing from us. We will then set your data to blocked.

e) Art. 19 Obligations of notification in connection with correction, deletion or restriction

We are obliged to inform all recipients of your data of any correction, deletion or restriction requested by you, insofar as this is possible and can be realized with a reasonable effort. We will inform you about the recipients of your data if you request this.

f) Art. 20 Right to data transfer

You have the right at any time to request our company to transfer your data to another responsible person. This refers to all master data that we keep about you. If technically possible, we will provide the data record in a common machine-readable format (e.g. .csv).

g) Art. 21 Right of objection

If a data processing has been justified on the basis of article 6, paragraph I, letter f (so-called legitimate interest), you may object to the processing in this context.

h) Art. 77 Right to appeal to a supervisory authority

You have the right to complain to the data protection supervisory authority responsible for our company at any time if you believe that we have violated the provisions of the GDPR in any way. The following authority is responsible for OneCinema GmbH:

Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18
91522 Ansbach - GERMANY

You can access the website of the data protection supervisory authority via the following link: https://www.lda.bayern.de/de/index.html

6. Processing operations

In this section we will describe the data processing that is connected with our internet offer or that applies to a general business relationship between you and our company.

The following legal bases serve us for the processing of your data.

Art. 6 I lit. a GDPR serves our company as a legal basis for processing operations for which we obtain consent for a specific processing purpose.

If the processing of your data is necessary for the performance of a contract to which you are a party, as is the case, for example, with processing operations required for the delivery of goods or the provision of other services or consideration, the processing is based on Art. 6 I lit. b GDPR. The same shall apply to such processing operations which are necessary for the performance of pre-contractual measures, for example in cases of inquiries about our products or services.

If our company is subject to a legal obligation which makes the processing of personal data necessary, for example to fulfil tax obligations, the processing is based on Art. 6 I lit. c GDPR.

In rare cases, the processing of personal data may be necessary to protect the vital interests of the person concerned or of another natural person. This would be the case, for example, if a visitor to our company was injured and his name, age, health insurance details or other vital information had to be passed on to a doctor, hospital or other third party. In this case the processing would be based on Art. 6 I lit. d GDPR.

Finally, processing operations could be based on Art. 6 I lit. f GDPR. Processing operations that are not covered by any of the above legal bases are based on this legal basis if the processing is necessary to protect a legitimate interest of our company or a third party, unless the interests, fundamental rights and freedoms of you outweigh the processing. We are permitted to carry out such processing operations in particular because they have been specifically mentioned by the European legislator.

a) Website processing

We operate this website and collect various data in this context.

Cookies

The Internet pages partly use so-called cookies. Cookies do not damage your computer and do not contain viruses. Cookies serve to make our offer more user-friendly, effective and safer. Cookies are small text files that are stored on your computer and saved by your browser.

Most of the cookies we use are so-called "session cookies". They are automatically deleted at the end of your visit. Other cookies remain stored on your end device until you delete them. These cookies enable us to recognize your browser on your next visit.

You can set your browser so that you are informed about the setting of cookies and allow cookies only in individual cases, exclude the acceptance of cookies for certain cases or in general and activate the automatic deletion of cookies when closing the browser. If you deactivate cookies, the functionality of this website may be limited.

Cookies that are required to carry out the electronic communication process or to provide certain functions that you have requested (e.g. shopping basket function) are stored on the basis of Art. 6 para. 1 lit. f GDPR. We, as website operators, have a legitimate interest in the storage of cookies for the technically error-free and optimized provision of our services. Insofar as other cookies (e.g. cookies to analyze your surfing behavior) are stored, they are treated separately in this privacy policy.

Server log data

OneCinema GmbH or our website provider collects data about access to our website and stores it as "server log files". The following data is logged in this way:

  • - Visited website
  • - Time at the time of access
  • - Amount of data sent in bytes
  • - Source/reference from which you reached to the page
  • - Used Browser
  • - Operating system used
  • - IP address used (anonymized)

The data collected is only used for statistical analysis and to improve the website. However, we reserve the right to check the server log files subsequently if there are concrete indications of illegal use.

Third party modules / analysis tools / advertising

Browser plug-in

You may refuse the use of cookies by selecting the appropriate settings on your browser, however please note that if you do this you may not be able to use the full functionality of this website. You can also prevent the collection of data generated by the cookie and related to your use of the website (including your IP address) to Google and the processing of this data by Google by downloading and installing the browser plugin available at the following link: https://tools.google.com/dlpage/gaoptout?hl=en.

(1) Facebook-Link

We have integrated a link to the Facebook web platform on this website. Facebook enables users of the social network to create private profiles, upload photos and network via friend requests.

The operating company of Facebook is Meta Platforms Inc, 1 Hacker Way, Menlo Park, CA 94025, USA. If a data subject lives outside the USA or Canada, the controller for the processing of personal data is Meta Platforms Ireland Ltd, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.

As soon as you use the Facebook link, your browser is redirected from our website to the Facebook platform. In this context, Facebook remembers from which of our sub-pages you switched to our Facebook fan page. If you are logged in to Facebook at the same time, Facebook will link your profile to our corporate website and remember this. This will also happen if you are logged into Facebook without leaving our website via a link.

If you do not want this information to be transmitted to Facebook in this way, you can prevent it from being transmitted by logging out of your Facebook account before accessing our website.

At https://developers.facebook.com/docs/plugins/?locale=en_US a complete overview of all Facebook plug-ins can be found.

The data policy published by Facebook, which is available at https://www.facebook.com/about/privacy/ , provides information about the collection, processing and use of personal data by Facebook. It also explains which settings Facebook offers to protect your privacy. In addition, various applications are available that make it possible to suppress data transmission to Facebook. Such applications can be used by you to suppress data transmission to Facebook.

Facebook collects so-called Insights data from every Facebook user; we do not use this data in any way for any analyses or evaluations. Unfortunately, we cannot prevent Facebook from collecting this data.

The Facebook link is used on the basis of Art. 6 para. 1 lit. f GDPR. We have a legitimate interest in the widest possible visibility in the social media.

(2) XING-Link

On this website we have integrated a link to the career platform Xing. Xing is an Internet-based social network that enables users to connect with existing business contacts and make new business contacts. Individual users can create a personal profile of themselves at Xing. Companies can, for example, create company profiles or publish job offers on Xing.

Xing's operating company is XING SE, Dammtorstraße 30, 20354 Hamburg, Germany.

Each time you call one of the individual pages on this website, which is operated by us and on which an Xing component (Xing plug-in) has been integrated, the Internet browser on the information technology system is automatically prompted by the respective Xing component to download a representation of the corresponding Xing component from Xing.

Further information on the Xing plug-ins can be found at https://dev.xing.com/plugins As part of this technical process, Xing obtains information about which specific subpage of our website you have visited.

If you are logged in to Xing at the same time, Xing recognizes with each change to the Xing page from which specific subpage of our website you made the change. This information is collected by Xing and assigned to its respective Xing account.

If you do not wish to transmit this information to Xing in this way, you can prevent its transmission by logging out of your Xing account before accessing our website.

The privacy policy published by Xing, which can be found at https://www.xing.com/privacy , provide information about the collection, processing and use of their personal data by Xing. Furthermore, Xing has published a privacy policy at https://www.xing.com/app/share?op=data_protection  for the XING-Share-Button.

The use of the Xing link is based on Art. 6 para. 1 lit. f GDPR. We have a legitimate interest in the widest possible visibility of our company in the social media and business platforms.

(3) LinkedIn-Link

We have included a link to LinkedIn Corporation on this website. LinkedIn is an Internet-based social network that allows users to connect with existing business contacts and to make new business contacts.

LinkedIn is operated by LinkedIn Corporation, 2029 Stierlin Court Mountain View, CA 94043, USA. For data protection matters outside the USA, LinkedIn Ireland, Privacy Policy Issues, Wilton Plaza, Wilton Place, Dublin 2, Ireland, is responsible for data protection issues.

Each time you access our website, which is equipped with a LinkedIn link, this link, when activated, causes your browser to transmit information such as (IP address and browser string) to LinkedIn. Further information about LinkedIn plug-ins can be found at https://developer.linkedin.com/plugins . As part of this technical process, LinkedIn receives information about which specific subpage of our website is visited by you.

If you are also logged in to LinkedIn, LinkedIn will recognize which specific page of our website you are visiting each time you access our website and throughout your visit to our website. This information is collected by LinkedIn and is associated with your LinkedIn account. When you click on a LinkedIn button on our website, LinkedIn will associate this information with your LinkedIn account and store this personal information.

LinkedIn will receive information from LinkedIn that you have visited our website if you are logged in to LinkedIn at the time you access our website, but only if you have clicked the LinkedIn link. If you do not want this information to be sent to LinkedIn, you can prevent it from being sent by logging out of your LinkedIn account and/or by not following the link to LinkedIn in the first place.

At https://www.linkedin.com/psettings/guest-controls LinkedIn provides the ability to unsubscribe from email messages, SMS messages, and targeted ads, as well as manage ad settings . LinkedIn also uses partners such as Quantcast, Google Analytics, BlueKai, DoubleClick, Nielsen, Comscore, Eloqua and Lotame who may set cookies. At https://www.linkedin.com/legal/cookie-policy such cookies can be rejected.

The applicable privacy policy of LinkedIn is available at https://www.linkedin.com/legal/privacy-policy LinkedIn's cookie policy can be found at https://www.linkedin.com/legal/cookie-policy .

b) Contact / Inquiries

In the following we describe the possibilities of contacting the companies and employees of our company.

Contact form

If you send us enquiries via the contact form, your details from the enquiry form including the contact data you provided there will be stored by us for the purpose of processing the enquiry and in the event of follow-up questions. These data will not be passed on without your consent.

The processing of the data entered in the contact form thus takes place in the first step on the basis of your consent (Art. 6 para. 1 lit. a GDPR). You can revoke this consent at any time. For this purpose, an informal e-mail notification to us is sufficient. The legality of the data processing operations carried out until the revocation remains unaffected by the revocation. In further correspondence, there may be a change of legality (e.g. if you request an offer), then your data will be processed in accordance with Art. 6 para. 1 lit b GDPR.

The data entered by you in the contact form will remain with us until you request deletion, revoke your consent to storage or the purpose for data storage no longer applies (e.g. after your request has been processed). Mandatory legal provisions - in particular retention periods - remain unaffected by this.

E-Mail / Phone inquiry

If you send us inquiries by e-mail or telephone, your data from the e-mail or conversation, including the contact data you provided there, will be stored by us for the purpose of processing the inquiry and in case of follow-up questions. We will not pass on this data without your consent.

The processing of the data provided in the e-mail or telephone conversation is therefore based on your consent (Art. 6 para. 1 lit. a GDPR). You can revoke this consent at any time. For this purpose, an informal communication by e-mail to us is sufficient. The legality of the data processing operations carried out up to the point of revocation remains unaffected by the revocation. In further correspondence, there may be a change in legality (e.g. if it is business correspondence), in which case your data will be processed in accordance with Art. 6 Para. 1 lit. b GDPR.

The data provided by you in the mail or from the telephone conversation will remain with us until you request us to delete it, revoke your consent for storage or the purpose for which the data was stored ceases to apply (e.g. after your inquiry has been processed). Mandatory legal provisions - in particular retention periods - remain unaffected by this.

c) Data processing for the fulfilment of contracts

If you have entered into a business relationship with our company, e.g. if you have placed an order with us, the data processing will be carried out on the basis of Art. 6 para. 1 lit. b GDPR. All data necessary to initiate, fulfill or complete this order, such as contact data, object data, service providers involved, photo documentation, plans, orders for goods, etc., may be collected and processed by us without separate consent.

Should it be necessary to call in a subcontractor (e.g. other IT service providers, special software suppliers) to fulfill the contract with you, we may also pass on your data to this subcontractor. We guarantee that we have committed our subcontractors to the same strict data protection requirements that you can expect from us.

In individual cases, it may happen that we obtain a company information from Creditrefom to initiate an order. If the data obtained in this way has consequences for the order, we will clarify this with you separately

In rare cases, we will also check individuals. For this purpose, our company randomly checks your creditworthiness when concluding contracts and, in certain cases where there is a legitimate interest, also with existing customers. For this purpose, we work together with Creditreform Boniversum GmbH, Hellersbergstraße 11, 41460 Neuss, from which we receive the necessary data. For this purpose, we transmit your name and contact details to Creditreform Boniversum GmbH. The information according to article 14 of the EU data protection basic regulation regarding data processing at Creditreform Boniversum GmbH can be found here: https://www.boniversum.de/eu-dsgvo/?lang=en

The data related to orders are subject to different retention periods. For example, general business letters must be proven for 6 years and tax law documents for 10 years. We will only pass on your data within our company to the extent necessary, if this is justified by the subject of the order.

d) Handling of applications Documents

Depending on the channel through which applications reach us, they will initially be processed by LUNISA trust & match GmbH, Industriestrasse 6b, 97359 Schwarzach am Main, Germany on behalf of OneCinema Solutions GmbH

The legal basis for the processing of your personal data for application purposes is § 26 of the BDSG.

Data is only collected and processed for this purpose to the extent required by law. Insofar as other data may not be directly required for the establishment of the employment relationship, the processing is based on a legitimate interest of the company in accordance with Art. 6 para. 1 lit. f GDPR.

A legitimate interest may arise, for example, from internal organizational and administrative purposes, for the protection of the company's facilities, installations and assets as well as data processing installations and data. A processing of your data is permitted here if the protection of your interests, basic rights and fundamental freedoms does not prevail.

In individual cases we can also obtain your consent to the processing or transmission of your data. Your consent is voluntary in these cases and can be revoked by you at any time in the future, unless otherwise agreed.

The application documents will be transmitted within the group of companies. The respective specialist department is thus involved in the application process. The specialist departments are instructed to treat application documents in strict confidence. The documents will not be transferred to a third country.

In this context LUNISA trust & match GmbH reserves the right to contact you in order to obtain your consent to the examination of your application documents for other vacancies which LUNISA trust & match GmbH is entrusted with. Your consent is given voluntarily and can be revoked by you at any time without giving reasons. This has no influence on your application to OneCinema GmbH.

OneCinema GmbH is the competent and responsible body for the collection, processing and use of your personal data.

Your personal data will only be stored as long as knowledge of the data is necessary for the above-mentioned purposes or as long as legal or contractual retention regulations exist. Application documents are usually deleted 6 months after the application process is completed.

It is possible to store your data for a longer period if you give us your consent. During this extended period, OneCinema GmbH may contact you about new job offers.

7. Protection / encryption

This site uses SSL or TLS encryption for security reasons and to protect the transmission of confidential content such as orders or inquiries that you send to us as the site operator. You can recognize an encrypted connection by the fact that the address line of the browser changes from "http://" to "https://" and by the lock symbol in your browser line.

If the SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.

8. profiling

As a responsible company, we avoid automatic decision making or profiling.

9. Actuality / status

This data protection declaration has the status of November 2023 and is subject to constant updating and adaptation to new legal framework conditions and technical developments.