In this Privacy Policy, we describe what personal data our website collects about you—whether directly from you or through our technology service providers—and how we handle your personal data.

1. Name and Contact Information of the Data Controller

EDEKA IT Stiftung & Co. OHG
New-York-Ring 6
22297 Hamburg

Contact

Email: info.edeka-it@edeka.de
Phone: +49 40 6377-0

2. Contact Information for the Data Protection Officer

You can reach our Data Protection Officer by mail

EDEKA IT Stiftung & Co. OHG
Data Protection Officer
New-York-Ring 6
22297 Hamburg

or by email: datenschutz.it[at]edeka.de

3. Purposes and Legal Bases for Data Processing

We process your personal data for the following purposes:

  • To provide our website and its features (Art. 6(1)(b) GDPR)
  • Data processing in connection with your job application (Art. 6(1)(b) GDPR)
  • To analyze and optimize our website (Art. 6(1)(f) GDPR)
  • To respond to contact inquiries (Art. 6(1)(b) or (f) GDPR)
  • To comply with legal obligations (Art. 6(1)(c) GDPR)

4. Categories of Processed Data

  • IP address
  • Date and time of the request
  • Browser type and version
  • Operating system
  • Referrer URL
  • Pages visited
  • Form data entered (e.g., in contact forms)

Depending on which service provider or technology is used on our website, additional personal data about you may be processed. If this is the case, these additional categories of personal data are described in more detail below in relation to the respective service provider or technology used (No. 3).

5. Contact Form and Email Contact

If you contact us via the contact form or by email, we will store your information to process your inquiry based on our legitimate interest (Art. 6(1)(f) GDPR). We will not disclose this data without your consent.

6. Data Processing of Job Applicants

You have the option to apply for advertised positions at EDEKA IT and, where applicable, other companies within the EDEKA Group via our career portal. By clicking the “Apply Now” button on job posting pages, you will be redirected to our applicant tracking system.

Personal data of applicants may be processed for the purposes of the application process if this is necessary to decide whether to establish an employment relationship with us (Art. 6(1)(b) GDPR).

The necessity and scope of data collection are determined, among other things, by the position to be filled. If the position you are applying for involves particularly confidential tasks or increased personnel and/or financial responsibility, more extensive data collection may be required. For this reason, we ask our applicants to provide us with a police clearance certificate. To ensure data protection, such data processing takes place either after the applicant selection process is complete, immediately prior to your hiring, or only after you have been hired.
If you have voluntarily given us your consent to the collection, processing, or transfer of certain personal data, then this consent forms the legal basis for the processing of this data (Art. 6(1)(a) GDPR).

In the following cases, we process your personal data based on your consent:

  • Inclusion in the applicant pool, i.e., we store your application documents beyond the current application process for consideration in future application processes.

In certain cases, we process your data to safeguard a legitimate interest of ours or of third parties (Art. 6(1)(f) GDPR):

  • To defend legal claims in proceedings under the General Equal Treatment Act (AGG). In the event of a legal dispute, we have a legitimate interest in processing the data for evidentiary purposes.

Your data is primarily processed by our Human Resources department and employees from the respective department responsible for filling your position. In some cases, however, other internal and external entities are also involved in the processing of your data.

Internal departments, depending on the job posting: Human Resources, team leaders, authorized signatories, Executive Board

External service providers: IT service providers (e.g., maintenance providers, hosting providers), document and data destruction service providers

We store your personal data for as long as necessary to make a decision regarding your application. If an employment relationship between you and us does not materialize, we may continue to store your data to the extent necessary to defend against potential legal claims. Your data is typically deleted within 6 months after the application process ends.

If an employment relationship is not established but you have given us your consent to continue storing your data, we will store your data until you revoke your consent, but for no longer than one year. In specific cases, we may also store your data for a longer period to defend against potential legal claims.

The provision of personal data is neither required by law nor by contract, nor are you obligated to provide such data. However, the provision of personal data is necessary for the application process to proceed. This means that if you do not provide us with personal data when applying, we will not be able to process your application.

7. Information About Service Providers and Technologies Used

We use various service providers and technologies to operate this website, which we would like to describe in more detail:

a) Hosting / Web Logs

Access logs and error logs are enabled on our server by default. Access log files record the activities of website visitors on the web pages. As the website operator, we collect this data to ensure the website functions properly, to detect attacks, and to protect ourselves against them. To this end, error logs record failed page requests. Where possible and appropriate, the IP address is pseudonymized by truncation. If an attack on our system is suspected, data about the visitor’s computer system is automatically logged for forensic analysis and stored in firewall logs. To this end, we process the following data: IP address, date and time of the website visit, browser user agent, hostname accessed, pages visited, status code, protocol (https, http), and request type (GET, POST, etc.). Firewall logs also record the type of attack. The collection of log files serves to log blocked or malicious website access attempts, to conduct forensic analysis of potential attacks on the website, and to ensure the security and stability of our website. The legal basis is Article 6(1)(f) of the GDPR; To the extent that access to information stored on the user’s terminal equipment is absolutely necessary, the legal basis is also Section 25(2)(2) of the TDDDG.

The purposes mentioned above also constitute a legitimate interest in data processing within the meaning of Article 6(1), first sentence, letter f) of the GDPR.

The data will be deleted as soon as it is no longer necessary to achieve the purpose for which it was collected. This is generally the case after one month at the latest.

To identify systemic issues on websites, it makes sense to store logs for more than 7 days. Errors often occur only sporadically and are therefore not detectable over short periods of time. The same applies to performance and security optimization: bots or crawlers that negatively impact our website often return at longer intervals. Within 30 days, we can classify them as either problematic or non-problematic.

To the extent that data is processed as described, this is strictly necessary for the security and operation of the website. You therefore have no right to object.

8. Recipients or Categories of Recipients

Your data will only be disclosed to the extent necessary to fulfill the purposes mentioned above (see No. 2). To the extent that external service providers have access to your personal data, we have ensured—through legal, technical, and organizational measures, as well as regular audits—that they comply with data protection laws. Furthermore, these service providers may only use your data in accordance with our instructions. In connection with the operation of our website, your data may be transferred to the following recipients:

  • IT service providers (e.g., maintenance service providers, hosting service providers, email providers)
  • Analytics and tracking services
  • Government authorities in accordance with legal obligations

9. Transfers to Third Countries

If data is transferred to third countries outside the EU, this is done only in compliance with Articles 44 et seq. of the GDPR, for example, based on an adequacy decision by the European Commission or using EU Standard Contractual Clauses. Further information is provided regarding the respective service providers or technologies used (see No. 3).

10. Retention Period

We store personal data only for as long as is necessary for the respective processing purposes or as required by statutory retention obligations. Server log files are generally stored for a maximum of one month.

11. Your Rights as a Data Subject

You have the following rights under the GDPR:

  • Information about the data processed
  • Correction of inaccurate data
  • Erasure (“right to be forgotten”)
  • Restriction of processing
  • Objection to processing (Art. 21 GDPR)
  • Data portability

Right to withdraw consent

If the processing is based on your consent (Art. 6(1)(a) GDPR), you may withdraw your consent at any time with future effect.

Right to lodge a complaint with a supervisory authority

You have the right to lodge a complaint with a data protection supervisory authority regarding the processing of your personal data if you believe that the processing of your personal data violates the GDPR.

The supervisory authority responsible for us is:

State Commissioner for Data Protection and Freedom of Information, Baden-Württemberg
P.O. Box 10 29 32
70025 Stuttgart