Data protection policy
Thank you for your interest in our company. Data protection is of the utmost importance to the board of PORR AG. PORR AG's websites may for the main part be used without submitting personal data. If a data subject wishes to avail themselves of specific services provided by our company via our website, this may necessitate the processing of personal data. If this is necessary, we will obtain the data subject's consent.
Personal data will always be processed subject to the provisions of the General Data Protection Regulation and in compliance with national data protection legislation. This data protection policy is designed to inform our users about the contents and purposes of the personal data that we collect and process. Furthermore, this data protection policy informs data subjects about the rights they are entitled to.
As the website operator, PORR AG has implemented an extensive number of technical and organisational measures in order to ensure that the data processed in connection with this website is reliably protected. However, there is always a possibility that data transmissions between your device and our server may feature security gaps, especially if the device you are using to communicate with our server can be accessed by third parties. If you have any concerns regarding security, you can use an alternative method, e.g. the telephone or one of our branch offices, to submit your information.
1. Definition of terms
PORR AG's data protection policy is based on the provisions and definitions of the General Data Protection Regulation (GDPR). Our data protection policy is designed to be easily readable and comprehensible for our visitors, clients and business partners. In order to ensure this, we would like to define the terms used beforehand:
1) Personal data
Personal data comprises all information relating to an identifiable natural person.
2) Data subject
A data subject is any identifiable natural person whose personal data is processed by a controller.
The controller is the company that collects the data subject's personal data and determines the purposes and means of processing.
The processor is a natural person or company involved by the controller in the processing of personal data.
The recipient is a natural or legal person, or public authority, to whom the personal data are disclosed.
6) Third party
A third party is a natural or legal person or public authority who processes personal data on behalf of the controller or processor.
Processing is any operation performed in connection with personal data. This ranges from the collection and storage to the restriction or erasure of personal data.
8) Restriction of processing
Restriction of processing means limiting the use of personal data.
Consent means any statement issued by a person to indicate that he or she agrees to the processing of personal data concerning him or her.
A person issuing a revocation revokes the right of the controller to process his or her data on the basis of consent.
Pseudonymisation separates the data from the identifiable person. This connection cannot be re-established without the use of additional, specially safeguarded information. The pseudonymisation process also corresponds to what is known as data minimisation.
Profiling is any form of automated evaluation of personal data.
2. Name and address of the controller
For the purposes of the GDPR, the controller is:
Tel: +43 50 626-0
3. Collection of data
Every time the PORR AG website is accessed, the website collects a variety of data and information which is then stored in the server's logfiles. The information collected in this manner includes, among other things:
1) Browser types and versions
2) Your computer's operating system
3) The website that linked you to us
4) Pages accessed on our web server
5) The date and time of your visit
6) Your IP address
7) Your Internet service provider
When using this anonymously collected information, PORR AG will not attempt to use it to identify the data subject. This data is, however, necessary in order to deliver the content of our website correctly, optimise the display, and provide the authorities with the necessary information in the event of a hacking attack. The data is therefore processed by PORR AG both statistically and as a technical measure to ensure data protection and information security of this processing and your data.
4. Registering on our website
You have the option of registering on our website. The data entered by the data subject is processed solely for the controller's internal use and purposes.
By registering on our website, the IP address assigned by your Internet service provider, the date, and the time of registration will be stored. This data will, in general, not be disclosed to third parties insofar as no legal disclosure obligations exist or disclosure is not required for the purposes of prosecution.
Registration allows us to offer you content and services which may only be offered to registered users. As a registered user, you may change your submitted data at any time or have it erased from our database in its entirety.
Cookies contain a cookie ID, which is an unambiguous identifier. They allow PORR AG to distinguish the data subject's browser from other Internet browsers, display content in an individualised manner and cater to the data subject's wishes and results.
The shopping basket cookie in the online shop is one example of this. The online shop uses a cookie to remember the items a customer has placed in the virtual shopping basket.
If you wish to prevent cookies from being set, you can define this in the security settings of your Internet browser, thereby permanently preventing the storage of cookies. Any cookies that are already on your computer can be deleted at any time via the Internet browser or directly from within the data system. Please be aware that deactivating cookies may result in limiting the set of functions provided by the website.
6. Subscribing to our newsletter
Users have the option of subscribing to our newsletter via our website. We use our newsletter to keep our customers and business partners informed about our offers at regular intervals. After you have registered, a confirmation email will be sent to the email address you have submitted, using the double opt-in method. This confirmation email serves to ensure that you, as the owner of the email address, have actually authorised delivery of the newsletter.
If you subscribe to the newsletter via our website, your email address, the IP address assigned by your Internet service provider, and the date and time of registration will be stored. This data will, in general, not be disclosed to third parties insofar as no legal disclosure obligations exist or disclosure is not required for the purposes of prosecution.
You can, of course, unsubscribe from our newsletter at any time. Please see the bottom of the newsletter for the necessary information.
7. Contacting us via the website
Due to legal provisions, our website contains information on how to easily contact PORR AG. If you contact us via email or a contact form, the data you have transmitted will be automatically stored and used solely for the purposes of replying to your message.
8. Routine erasure and blocking of personal data
PORR AG shall process and store the personal data of the data subject only for the period necessary to achieve the purpose of storage, or insofar as this is granted by legal provisions.
If the storage purpose or the legal basis are no longer given, your personal data will be blocked or erased on the basis of our processes and in accordance with legal requirements.
9. Rights of the data subject
Comprehensive rights of the data subject apply for the processing of personal data, in accordance with the EU-GDPR. A general list of these rights is provided below for your information:
1) Right of access
Every data subject shall at any time have the right to obtain information about the stored personal data concerning him or her as well as a copy of this information from the controller.
2) Right to rectification
Every data subject shall have the right to obtain the rectification or completion of inaccurate personal data concerning him or her from the controller without delay.
3) Right to erasure
Every data subject shall have the right to obtain from the controller the erasure of personal data concerning him or her, where one of the following grounds applies
- The purposes for processing no longer exist
- The legal grounds for processing no longer exist (termination of the contract, revocation of consent)
Please contact one of our staff members at any time - in particular by electronic means via firstname.lastname@example.org - to obtain erasure of your data stored by us.
4) Right of restriction
Every data subject affected by the processing of personal data shall have the right to obtain from the controller restriction of processing where one of the following applies:
- The purposes for processing no longer exist
- The legal grounds for processing no longer exist (termination of the contract, revocation of consent)
Please contact one of our staff members at any time - in particular by electronic means via email@example.com - to obtain restriction of processing of your data stored by us.
5) Right of data portability
Every data subject shall have the right to receive the personal data that he or she has personally provided to a controller, in a structured, commonly used and machine-readable format, and to transmit those data to another controller without hindrance from the original controller, if the processing is based on consent or on a contract and is carried out by electronic means.
Please contact one of our staff members at any time - in particular, by electronic means via firstname.lastname@example.org - to obtain transmission of your data stored by us.
6) Right to object
Every data subject shall have the right to object to the processing of personal data concerning him or her based on legitimate interests. In the event of an objection, PORR AG will no longer process the personal data, unless we can demonstrate compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject, or for the establishment, exercise or defence of legal claims.
Please contact one of our staff members at any time - in particular, by electronic means via email@example.com - to exercise your right to object.
7) Automated individual decision-making, including profiling
As a responsible company, we refrain from automated decision-making and profiling.
8) Right to revoke consent
Every data subject shall have the right to revoke his or her consent to the processing of his or her personal data at any time.
Please contact one of our staff members at any time - in particular by electronic means via firstname.lastname@example.org - to exercise your right to revoke consent.
10. Data protection relating to applications and during the application process
The controller collects and processes applicants' personal data for the purposes of implementing the application process. This processing may also be undertaken by electronic means. This applies in particular, in cases where the applicant submits their respective application documents to the controller by electronic means, for example, via email or via the careers portal porr-group.com/en/karriere. If PORR AG enters into a service contract with an applicant, the submitted data will be stored for the purposes of implementing the employment relationship. If PORR AG does not enter into a service contract with the applicant, the applicant’s application documents will be automatically deleted, at the latest, six months after he or she is notified of this decision, insofar as this is not precluded by other legitimate interests of PORR AG or the applicant's consent to further processing. If your application is not targeted towards a specific role listed in the careers portal (speculative application), your data may be forwarded on to a company within the PORR Group, depending on your qualifications, to satisfy mutual, legitimate interests.
What data are collected?
The following data are collected and processed for the automatic processing of your application:
1) First name, last name, email address and address/place of residence, if applicable, date of birth, title, telephone number, nationality
2) Additional questions, depending on the respective job offer (e.g. driver's licence)
3) CV, in particular, information regarding your professional experience and education
4) Professional experience and education
5) Skills (e.g. Photoshop, MS Office)
6) Application photo
7) Qualifications, awards and language skills
8) Cover letter
9) Any data and documents you may have uploaded
11. Data protection provisions concerning the application and use of Facebook
Our website contains plugins provided by Facebook, 1601 South California Avenue, Palo Alto, CA 94304, USA. Facebook is a social network. The respective plugin can be identified by the Facebook logo or the "like" button. An overview of all of the Facebook plugins is provided under the following link: developers.facebook.com/docs/plugins
As soon as you visit our website, the Facebook plugin creates a direct connection between your Internet browser and Facebook's servers. This informs Facebook that our website was accessed by your IP address. If you are logged into Facebook, you can link the content on our website to your Facebook profile by clicking on the "like" button. Facebook will then be able to assign your visit to our website to your Facebook account. Facebook does not inform us, as the providers of our website, of the content of the transmitted data or the data usage. For more information, please click on the following link:
If you are a member of Facebook but do not want data concerning you to be transmitted to Facebook via our website and linked to your membership data, please sign out of Facebook before viewing our website.
12. Data protection provisions concerning the application and use of Google Analytics (with anonymisation function)
Our website uses Google Analytics. This is a web analysis service operated by Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. Google Analytics uses so-called cookies. Cookies are files. By storing cookies on your computer, Google can analyse your usage of our website. This information and your anonymised IP address are transmitted to Google's servers in the USA and stored there.
We use the application “_gat. _anonymizeIp” for web analytics via Google Analytics. This abbreviates and anonymises your IP address.
Google evaluates the information relating to your use of our website. Reports on your activities on our website are created and provided to us. This can also serve the purpose of allowing us to offer or provide other services concerning the use of our website or the Internet. Google may pass this information on to a third party if this is legally required or if said third party has been commissioned by Google to process this data.
You can prevent these cookies from being stored on your computer by adjusting the settings of your Internet browser accordingly. This may, however, restrict your use of our website. You may also prevent Google from collecting, transmitting and processing your data and IP address. To do so, please download and install a plugin for your Internet browser. This plugin is available under the following link: http://tools.google.com/dlpage/gaoptout?hl=de
13. Data protection provisions concerning the application and use of LinkedIn
Our website features plugins provided by the social network LinkedIn, or the LinkedIn Corporation, 2029 Stierlin Court, Mountain View, CA 94043, USA (hereinafter referred to as "LinkedIn"). The LinkedIn plugins can be identified by the corresponding logo or the "recommend" button. Please be aware that the plugin creates a direct connection between your respective Internet browser and LinkedIn's server when you visit our website. This informs LinkedIn that our website has been viewed from your IP address. If you click on LinkedIn's "recommend" button while signed into LinkedIn, you can link content from our web pages to your LinkedIn profile. This allows LinkedIn to assign your visit to our website to you or your user account. Please be aware that we are not informed of the content of the transmitted data and how this is used by LinkedIn.
Further details concerning the collection of data, your legal options, and settings options can be obtained from LinkedIn. These details can be viewed under www.linkedin.com/legal/privacy-policy
14. Data protection provisions concerning the application and use of Shariff
PORR AG has integrated the component Shariff on this website. The Shariff component provides social media buttons that comply with data protection provisions. Shariff was developed for the German computer journal c't and is published via GitHub, Inc.
The developer of the component is GitHub, Inc. 88 Colin P. Kelly Junior Street, San Francisco, CA 94107, USA.
The button solutions provided by the social networks themselves generally transmit personal data to the respective social network whenever the user visits a website where a social media button has been integrated. By using the Shariff component, personal data are not transmitted to social networks unless the website user actively clicks on one of the social media buttons. The computer journal c't provides further information on the Shariff component under www.heise.de/newsticker/meldung/Datenschutz-und-Social-Media-Der-c-t-Shariff-ist-im-Einsatz-2470103.html. Using the Shariff component serves to protect the personal data of visitors to our website while at the same time enabling us to integrate a button solution for social networks into this website.
Further information and the data protection provisions that apply for GitHub can be viewed under help.github.com/articles/github-privacy-policy/.
15. Data protection provisions concerning the application and use of Twitter
PORR AG's website incorporates functions provided by Twitter Inc., 795 Folsom Street, Suite 600, San Francisco, CA 94107, USA. If you use Twitter and, in particular, the "retweet" function, Twitter will link your Twitter account to the websites you have frequented. Other Twitter users, particularly your followers, are notified of this. Data is also transmitted to Twitter in this way.
Twitter does not inform us, as the providers of our website, of the content of the transmitted data, nor of how it uses the data. Please click on the following link for further information: twitter.com/privacy
However, please be aware that you have the option of changing your data protection settings for Twitter in the settings for your Twitter account under twitter.com/account/settings.
16. Data protection provisions concerning the application and use of XING
This website uses the XING "share" button. By accessing this website, a connection is made from your browser to the servers of XING AG, Gänsemarkt 43, 20354 Hamburg, Germany. This allows the share functions (e.g. displaying the counter value) to be carried out. It does not store your personal data via your visit to this website. In particular, XING does not store IP addresses. Nor does it evaluate your usage patterns. For up-to-date information on data protection concerning the "share" button and other relevant information on this topic, please click on the following link: www.xing.com/app/share
17. Data protection provisions concerning the application and use of YouTube
This website contains at least one YouTube plugin. YouTube is operated by the company YouTube, LLC, 901 Cherry Ave., San Bruno, CA 94066, USA. YouTube, LLC is a subsidiary of Google Inc., 1600 Amphitheatre Pkwy, Mountain View, CA 94043-1351, USA.
As soon as you view one of the pages of our website that features a YouTube plugin, a connection to YouTube's servers is established. YouTube's servers are informed of which specific page of our website you have visited. If you are also signed into your YouTube account, this allows YouTube to assign your browsing patterns directly to your personal profile. You can rule out this possibility by logging out of your account before visiting our web pages. Please see YouTube's data protection provisions under policies.google.com/privacy for more information on how YouTube collects and uses your data.
18. Data protection provisions concerning the application and use of whatchado
PORR AG has integrated whatchado components into this website. whatchado is a career platform which matches companies with suitable job candidates.
whatchado is operated by the company whatchado GmbH, Möllwaldplatz 4/39 1040 Vienna, Austria.
Every time one of the individual pages of this website, which is operated by the controller and into which a whatchado page (web pages and videos) has been incorporated, the corresponding whatchado component automatically instructs the Internet browser on the data subject's IT system to download a diagram of the respective whatchado component. Further information on whatchado is available under www.whatchado.com/en/about-us. As part of this technical procedure, whatchado is informed of which specific subpage of our website is currently being viewed by the data subject.
If the data subject is logged into whatchado while viewing a subpage of our website that contains a whatchado video, whatchado will identify which specific subpage the data subject is currently viewing. This information is collected by whatchado and assigned to the data subject's respective whatchado account.
The whatchado component always informs whatchado that the data subject has viewed our website if the data subject is simultaneously logged into whatchado, regardless of whether or not the data subject clicks on a whatchado video. If the data subject does not want this information to be transmitted to whatchado, he or she can prevent transmission by logging out of his or her whatchado account before viewing our website.
Information on how whatchado collects, processes and uses personal data is provided in the whatchado data protection provisions, which can be viewed under www.whatchado.com.
19. Data protection provisions concerning the application and use of kununu.
PORR AG has integrated components provided by kununu into this website.
With a total of 2.4 million reviews of over 650,000 companies to date, kununu is Europe's largest employer review sites. kununu is operated by the company kununu GmbH, a subsidiary of XING SE, Dammtorstraße 30, 20354 Hamburg, Germany. Every time one of the individual pages of this website, which is operated by the controller, and into which a kununu component has been incorporated, the corresponding kununu component automatically instructs the Internet browser on the data subject's IT system to download a diagram of the respective kununu component. As part of this technical procedure, kununu is informed of which specific subpage of our website is currently being viewed by the data subject.
If the data subject is logged into kununu while viewing our website, kununu will identify which specific subpage the data subject is currently viewing every time the website is accessed by the data subject and for the entire viewing period. This information is collected by the kununu component and assigned to the data subject's respective kununu account by kununu. If the data subject clicks on one of the buttons integrated into our website, for example the "rate employer" button, kununu will assign this information to the data subject's personal kununu user account and store this personal data.
The kununu component always informs kununu that the data subject has viewed our website if the data subject is simultaneously logged into kununu, regardless of whether or not the data subject clicks on the kununu component. If the data subject does not want this information to be transmitted to kununu, he or she can prevent transmission by logging out of his or her kununu account before viewing our website.
Information on how kununu collects, processes and uses personal data is provided in the data protection provisions that apply for kununu, which can be viewed under privacy.xing.com/en.
20. Forwarding data
PORR AG may issue instructions for your contact data to be forwarded on to one or more processors, for example a parcel service provider, who will also use the personal data exclusively for internal purposes, which are to be ascribed to the controller.
Our contracts with all the relevant processors ensure that these service providers also comply with the provisions of the GDPR.
21. Legal basis for processing
The legal basis for processing personal data on our website is either our legitimate interest in acquiring you as a future customer, e.g. as a pre-contractual measure, informing you of our products and services, or to fulfil our contractual obligations towards you as the data subject, if an order has been placed that would necessitate the delivery of goods. Legal retention obligations or the obligation to provide statements to government authorities may, as a result, become a legal basis, in and of themselves.
We will obtain your revocable consent for all other processing operations, e.g. newsletters.
22. Period for which the personal data will be stored
The storage of personal data is limited to the statutory retention period. After this period has expired, the corresponding data will be deleted, insofar as it is no longer necessary for the fulfilment of the contract or the initiation of a contract.