Skip to main content

Processing of (personal) data by the entity in charge of the online application process

Privacy notice

This Privacy Notice explains how personal data (“Data”) provided by you to - and collected by – Magirus GmbH (“we”, “us”, “our”, or the “Company”) through this website will be handled in compliance with applicable laws and regulations. We are committed to protecting and respecting your privacy.

1. HOW WE OBTAIN DATA

Data that may be collected, processed and stored are the following:
  1. Data provided by you to us in order for you to receive a specific service or as part of business relationship (such as identification and contact information, professional data)
  2. Browsing Data or data arising from you interacting with our website
  3. Cookies (please refer to the Cookie policy, linked above, which explains the use of cookies and other web tracking devices via our website)
Ordinarily, you will have provided such Data to us, but in some cases, we may collect Data about you from a third party or from public records. We protect Data obtained from such third parties according to the practices described in this privacy notice.

2. HOW WE USE DATA

Data collected may be processed by us for the following purposes:
  • Fulfilling your requests by providing information about our products, services, offers and commercial network;
  • Pursuing our interest to establish, maintain and improve our relationship with you
Data is collected and processed on the basis of the contract under point (1) and our legitimate interest for the processing under points (2).
Data may be processed electronically within IT systems, and manually, in paper form. Data will be processed and stored for its whole lifecycle, ensuring security and confidentiality of the same in compliance with principles of fairness, lawfulness and transparency and in accordance with the provisions of applicable laws and regulations.

3. CONSEQUENCES OF FAILURE TO PROVIDE DATA

Submitting Data is never mandatory. However, not providing Data that is necessary to provide a service or product and that is marked as mandatory may prevent us from providing the required service or the product or may result in suboptimal provision of the required service or product. On the other hand, not providing Data whose provision is marked as optional will allow you to access the service or to receive the product in any event.

4. HOW WE SHARE YOUR DATA

We are part of the Iveco Group, a global leader in the capital goods sector. Data may be shared and communicated to our subsidiaries and affiliates of the Iveco Group, trusted external parties, service providers, authorized dealers and distributors and business partners, based in and outside the European Union, which are under specific contractual obligation and may use it solely for the fulfillment of the purposes listed above.
Date may be communicated to third parties to comply with legal obligations, to operate and maintain our and the Iveco Group security, protect our and the Iveco Group rights or property, to respond to order of Public Authorities, or to exercise our rights before judicial authorities.
Additional processing of data mentioned in paragraph 1 of this Privacy Notice are carried out by other Controllers:
  • This website uses external fonts, so-called web fonts, in the interest of an appealing presentation of our online offers. These web fonts are a service of Monotype Imaging Holding Inc. ("Monotype"). These web fonts are integrated by a server call, usually a Monotype server in the USA. This transfers to the server which of our Internet pages you have visited. Monotype also stores the IP address of the browser of the visitor's terminal device as well as his page views for billing purposes. For more information, please see Monotype's privacy policy.
  • No social media plugins are set, but so-called social bookmarks. After clicking on the integrated graphic, the user is forwarded to the page of the respective provider. In addition, if an internet page is forwarded via the "Share this content" button, it is possible that the corresponding internet page becomes visible on Twitter, Facebook etc. and can be viewed there as an activity in the user's profile.
  • We have integrated YouTube videos into our online offering, which are stored on www.YouTube.com and can be played directly from our website. These are all integrated in the "extended data protection mode", i.e. no data about you as a user will be transmitted to YouTube if you do not play the videos. Only when you play the videos, the data mentioned under paragraph 1 will be transmitted. We have no influence on this data transmission. By visiting the website, YouTube receives the information that you have accessed the corresponding subpage of our website. In addition, the data mentioned in paragraph 1 of this declaration will be transmitted. This is regardless of whether this third party provides a user account through which you are logged in, or whether no user account exists. If you are logged in to Google, this information will be directly associated with your account. If you do not wish to be associated with your profile on YouTube, you must log out before activating the button. YouTube stores these data as user profiles and uses them for the purposes of advertising, market research and/or demand-oriented design of its website. Such evaluation takes place in particular (even for unlogged-in users) to provide demand-oriented advertising and to inform other users of the social network about your activities on our website. You have the right to object to the creation of these user profiles, whereby you must contact YouTube to exercise this right. Third-party information: YouTube LLC, 901 Cherry Ave., San Bruno, CA 94066, USA: https://policies.google.com/technologies/product-privacy?hl=en  and  https://www.google.de/intl/de/policies/privacy.  Google also processes your personal data in the USA and has submitted to the EU-US Privacy Shield, www.privacyshield.gov/EU-US-Framework.

5. HOW WE TRANSFER YOUR DATA

In order to perform Data processing activities as detailed above, we may transfer Data in countries outside of the European Economic Area (EEA), including storing such Data in digital or physical databases managed by entities acting on our behalf. Database management and Data processing are limited to the purposes of the processing and are carried out according to applicable data protection laws and regulations.
In case Data are transferred outside of the EEA, the Company will use any appropriate contractual measures to guarantee adequate protection of the Data, including – among others – agreements based on Standard Data Protection Clauses adopted by the EU Commission applicable to the transfer of personal data outside the EEA.

6. RETAINING YOUR PERSONAL DATA

We maintain Data in our systems and archives for as long as necessary to pursue the purposes described in this Privacy Notice taking into account, when applicable, legal and contractual requirements.
When Data is no longer necessary for the purposes for which it is processed, Data is deleted or kept in a form which does not permit the identification of data subjects, provided that we are not legally required or permitted to hold such Data. We may continue to store Data for a longer period, as may be necessary to protect our interests related to potential liability connected to the provision of the services or products or the processing of Data.

7. DATA CONTROLLER

Magirus GmbH with registered office in Graf-Arco-Straße 30, 89079  Ulm – Germany is the Controller for the Data it collects, processes and stores in the framework of this Privacy Notice. 
Magirus GmbH has appointed a Data Protection Officer. The contact information of the Data Protection Officer is as follows:
Magirus GmbH 
Data Protection Officer 
Graf-Arco-Straße 30 
89079 Ulm, Germany
Phone: + 49 731 408-0 
E-mail: datenschutz@magirus.com

8. YOUR RIGHTS REGARDING YOUR DATA

You may exercise your rights as defined by applicable laws and regulations, among these:
  • Right of access: right to obtain from the Controller a confirmation as to whether or not your personal information is being processed, and, if so, to demand to gain access to your personal data.
  • Right to rectification: right to obtain from the Controller the rectification of your personal data that you may consider inaccurate and to have incomplete information being completed, including by means of providing a supplementary statement.
  • Right to erasure: right to obtain from us the erasure of your personal data without undue delay, where the request is made in accordance with the applicable laws and regulations.
  • Right to object to data processing: right to object at any time to the processing of your personal data based on the legitimate interest of the Controller.
  • Right to limit the data processing: right to obtain from the Controller a limitation on the processing activities when the accuracy and the precision of personal data is disputed, and for the time necessary for the Controller to verify the accuracy of personal data.
  • Right to data portability: right to receive the personal data you provided to the Controller in a structured, commonly used and machine-readable format. You also have the right to transmit that data to another data controller without hindrance from the Controller, especially following these conditions: the processing is based on consent or on a contract and the processing is carried out by automated means.
  • Right to make a complaint: without prejudice to any other administrative or judicial dispute, if you believe the data processing has been carried out illicitly or not compliant with applicable laws and regulations, you have the right to raise a complaint with the Supervisory Authority of the Member State in which you reside or work habitually, or of the State where any breach has occurred.
You can exercise the abovementioned rights by contacting us as follows:
  • Sending a letter to the Data Protection Officer – Magirus GmbH, Data Protection Officer, Graf-Arco-Straße 30, 89079 Ulm, Germany, attaching the standard form that you can download from here
  • Writing an email to privacy-compliance@ivecogroup.com,
  • Sending a letter to the Controller at the address indicated in the section 7 of this Privacy Notice, specifying “for the attention of Privacy Compliance”
Should you send us a request, we may need to obtain additional personal information from you to verify your identity and contact you, if necessary. This information, together with other Data we already withhold, will then be processed to meet your request, as required by applicable law. Where necessary, certain information may be transferred to other companies within or outside the Iveco Group that act as data processors of your Data, in order to meet your request. Your Data will be processed for the necessary amount of time to evaluate and handle your request, after which your Data will be archived for a suitable time period allowing us to demonstrate that the request has been handled correctly and timely.

9. UPDATES OF THIS PRIVACY NOTE

This Privacy Notice was updated in January 2022. We reserve the right to amend or update the Privacy Notice from time to time to reflect changing legal requirements or our processing activities. We will publish any update on this website and it will be effective upon posting. We encourage you to periodically review this Privacy Notice to learn how we protect your Data.

Processing of (personal) data by the operator of the recruitment website

General information

This recruitment website is operated by Personio SE & Co. KG, which offers a human resource and candidate management software solution (https://www.personio.com/legal-notice/). Data transmitted as part of your application will be transferred using TLS encryption and stored in a database. The sole controller of this data within the meaning of article 24 of the GDPR is the enterprise carrying out this online application process. Personio’s role is limited to operating the software and this recruitment website and, in this context, being a processor under article 28 of the GDPR. In this case, the processing by Personio is based on an agreement for the processing of orders between the controller and Personio. In addition, Personio SE & Co. KG processes further data, some of which may be personal data, to provide its services, in particular for operating this recruitment website. We will refer to this in more detail below.

The controller

The controller under data protection law is:
Personio SE & Co. KG
Seidlstraße 3
80335 München
Tel.: +49 (89) 1250 1004
Entry in the commercial register
Commercial register entry number: HRA 115934
Registration Court: Amtsgericht München
Data Protection Officer contact: privacy@personio.com

Access logs (“server logs”)

Each access to this recruitment website automatically causes general protocol data, so-called server logs, to be collected. As a rule, this data is a pseudonym and thus does not allow for inferences about the identity of an individual. Without this data, it would, in some cases, be technically impossible to deliver or display the contents of the software. In addition, processing this data is absolutely necessary under security aspects, in particular for access, input, transfer, and storage control. Furthermore, this anonymous information can be used for statistical purposes and for optimizing services and technology. In addition, the log files can be checked and analyzed retrospectively when unlawful use of the software is suspected. The legal basis for this is §25 subsection 2 Sentence 2 TDDDG. Generally, data such as the domain name of the website, the web browser and web-browser version, the operating system, the IP address, as well as the timestamp of the access to the software is collected. The scope of this log process does not exceed the common log scope of any other site on the web. These access logs are stored for a period of up to 7 days. There is no right to object to this.

Error logs

So-called error logs are generated for the purpose of identifying and fixing bugs. This is absolutely necessary to ensure we can react as quickly as possible to possible problems with displaying and implementing content (legitimate interest). As a rule, this data is a pseudonym and thus does not allow for inferences about the identity of an individual. The legal basis for this is §25 subsection 2 Sentence 2 TDDDG. When an error message occurs, general data such as the domain name of the website, the web browser and web-browser version, the operating system, the IP address, as well as the timestamp upon occurrence of the respective error message and/or specification is collected. These error logs are stored for a period of up to 7 days. There is no right to object to this.

Use of cookies

So-called cookies are used on parts of this recruitment website. They are small text files which are stored on the device with which you access this recruitment website. As a general rule, cookies serve the purpose of ensuring secure access to a website (“absolutely necessary”), implementing certain functionalities such as standard-language settings (“functional”), improving the user experience or the performance of the website (“performance”), or placing targeted advertisements (“marketing”). On this recruitment website, we generally use only cookies that are absolutely necessary, functional or performance-related, in particular for implementing certain default settings such as language, for identifying the job advertising channel, or for analyzing the performance of a job advert via which a user accessed this recruitment website. The use of cookies is absolutely necessary for providing our services and thus for the performance of the contract (article 6 (1) b) of the GDPR). Period of storage: up to 1 month or until the end of the browser session Right to object: You can determine via your browser settings whether you allow or object to the use of cookies. Please note that deactivating cookies may result in limited or completely blocked functionalities of this recruitment website.

Rights of data subjects

If Personio SE & Co. KG as the controller processes personal data, you as the data subject have certain rights under Chapter III of the EU General Data Protection Regulation (GDPR), depending on the legal basis and the purpose of the processing, in particular the right of access (article 15 of the GDPR) and the rights to rectification (article 16 of the GDPR), erasure (article 17 of the GDPR), restriction of processing (article 18 of the GDPR), and data portability (article 20 of the GDPR), as well as the right to object (article 21 of the GDPR). If the personal data is processed with your consent, you have the right to withdraw this consent under article 7 III of the GDPR. To assert your rights as a data subject in relation to the data processed for the purpose of operating this recruitment website, please refer to Personio SE & Co. KG’s Data Protection Officer (see item B).

Concluding provisions

Personio reserves the right to adjust this data privacy statement at any point in time to ensure that it is in line with the current legal requirements at all times, or in order to accommodate changes in the services offered, for example when new services are introduced. In this case, the new data privacy statement applies to any later visit of this recruitment website or any later job application.