Verfahrenstechnik | Umweltschutz | Anlagenbau | Maschinenbau
+49 8542 165-0
Königbacher Straße 17 · D-94496 Ortenburg

Privacy Policy

Privacy policy of R. Scheuchl GmbH on the processing of personal data as well as privacy information for the RS.ERP mobile app.

Data Protection

Protecting your privacy when processing personal data is an important concern for us. When you visit our website, our web servers store by default the IP of your Internet Service Provider, the website from which you visit us, the web pages you visit on our site, as well as the date and duration of your visit. This information is strictly necessary for the technical transmission of the web pages and secure server operation. A personalised evaluation of this data does not take place.

Your data is treated in strict confidence. It is not passed on to third parties.

Personal Data

“Personal” data exists when it contains individual information about the personal or material circumstances of an identified or identifiable person; this includes in particular name and address, IP address and the like. The “collection” of data means the acquisition of data. “Processing” means the storage, modification, transmission, blocking and deletion of data. The term “use” means any further use that does not fall under processing.

You also do not have to disclose any personal data in order to be able to visit our website. In some cases we require your name and address as well as further information in order to be able to offer you the desired service.

The same applies in the event that we supply you with information material on request, or when we answer your enquiries. In these cases we will always point this out to you. In addition, we only store the data that you have transmitted to us automatically or voluntarily.

Data Protection in Applications and the Application Process

We collect and process the personal data of applicants for the purpose of handling the application process. Processing may also take place by electronic means. This is particularly the case when an applicant submits corresponding application documents by electronic means, for example by email. If the controller concludes an employment contract with an applicant, the transmitted data is stored for the purpose of handling the employment relationship in compliance with the statutory provisions. If the controller does not conclude an employment contract with the applicant, the application documents are automatically deleted six months after notification of the rejection decision, unless the data subject has consented to longer storage or unless other legitimate interests of the controller preclude deletion. A legitimate interest in this sense is, for example, a burden of proof in proceedings under the General Equal Treatment Act (AGG).

Automatically Stored Non-Personal Data

With every access by a user and with every retrieval of a file, data about this process is stored in a log file. The storage serves exclusively internal system-related and statistical purposes.

Specifically, the following data record is stored for each retrieval:

  • Name of the retrieved file
  • Date and time of the retrieval
  • Amount of data transmitted
  • Message as to whether the retrieval was successful
  • Description of the type of web browser used
  • Requesting domain

This data is anonymised and used only for statistical purposes or to improve our internet and online services.

This anonymised data is stored – separately from personal data – on secure systems and cannot be assigned to individual persons. This means that your personal data remains protected at all times.

Cookies

This website does not use cookies for tracking, analytics or advertising purposes and does not integrate any web-analytics services (e.g. Google Analytics). Visitors are not recognised via cookies.

Embedded third-party content is loaded solely to display the content: videos via YouTube in privacy-enhanced mode (youtube-nocookie.com) and the location map via OpenStreetMap. When this content is loaded, your IP address may be transmitted to the respective provider.

Security

We have taken technical and administrative security precautions to protect your personal data against loss, destruction, manipulation and unauthorised access. All our employees as well as service providers working for us are obliged to comply with the applicable data protection laws.

Whenever we collect and process personal data, it is encrypted before being transmitted. This means that your data cannot be misused by third parties. Our security precautions are subject to a continuous improvement process and our privacy policies are constantly revised. Please ensure that you have the latest version.

Data Transfer

Personal data is only passed on to third parties or otherwise transmitted if this is necessary for the purpose of contract processing / billing purposes or if the data subject has previously consented.

Otherwise, data is only passed on under the statutory provisions of data protection or upon request by authorities, courts and the tax office, or in the event of a claim by a third party on the basis of a possible infringement of protective rights (copyright, trademark and other ancillary copyrights) by a holder of protective rights.

Personal data is not transferred to or in third countries.

Rights of Data Subjects

a) Right of Access

Every data subject has the right to receive free information about the personal data stored about them. In detail:

  • the processing purposes
  • the categories of personal data that are processed
  • the recipients or categories of recipients to whom the personal data has been or will be disclosed, in particular recipients in third countries or international organisations
  • if possible, the planned duration for which the personal data will be stored, or, if this is not possible, the criteria for determining this duration
  • the existence of a right to rectification or erasure of the personal data concerning them, or to restriction of processing by the controller, or a right to object to such processing
  • the existence of a right to lodge a complaint with a supervisory authority
  • if the personal data is not collected from the data subject: all available information about the origin of the data
  • the existence of automated decision-making, including profiling, pursuant to Article 22(1) and (4) GDPR and – at least in these cases – meaningful information about the logic involved as well as the scope and intended effects of such processing for the data subject

b) Right to Rectification

Every data subject has the right to request the rectification of their data. Furthermore, the data subject has the right, taking into account the purposes of the processing, to request the completion of incomplete personal data – also by means of a supplementary declaration.

c) Right to Erasure

Every data subject has the right to request that the controller erase the personal data concerning them without undue delay. In place of erasure, archiving or blocking takes place, insofar as statutory retention periods preclude erasure.

d) Right to Restriction of Processing

Every data subject has the right to request the restriction of processing from the controller if one of the following conditions applies:

  • The accuracy of the personal data is contested by the data subject, for a period enabling the controller to verify the accuracy of the personal data.
  • The processing is unlawful, the data subject opposes the erasure of the personal data and requests instead the restriction of the use of the personal data.
  • The controller no longer needs the personal data for the purposes of the processing, but the data subject requires it for the establishment, exercise or defence of legal claims.
  • The data subject has objected to the processing pursuant to Art. 21(1) GDPR and it is not yet clear whether the legitimate grounds of the controller override those of the data subject.

e) Right to Data Portability

Every data subject has the right to receive the personal data concerning them, which has been provided to a controller by the data subject, in a structured, commonly used and machine-readable format. This includes the right to transmit this data to another controller without hindrance from the controller to whom the personal data was provided, provided that the processing is based on consent pursuant to Art. 6(1)(a) GDPR or Art. 9(2)(a) GDPR, or on a contract pursuant to Art. 6(1)(b) GDPR, and the processing is carried out by automated means, provided that the processing is not necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.

Furthermore, in exercising their right to data portability pursuant to Art. 20(1) GDPR, the data subject has the right to have the personal data transmitted directly from one controller to another, insofar as this is technically feasible and provided that the rights and freedoms of other persons are not adversely affected.

f) Right to Object

Every data subject has the right to object, on grounds relating to their particular situation, at any time to the processing of personal data concerning them which is based on Art. 6(1)(e) or (f) GDPR. This also applies to profiling based on these provisions.

g) Right to Non-Automated Processing, Including Profiling

Every data subject has the right not to be subject to a decision based solely on automated processing (including profiling) which produces legal effects concerning them or similarly significantly affects them, provided that the decision:

  • is not necessary for entering into, or the performance of, a contract between the data subject and the controller,
  • is authorised by Union or Member State law to which the controller is subject and which lays down suitable measures to safeguard the data subject’s rights and freedoms and legitimate interests, or
  • is based on the data subject’s explicit consent.

h) Right to Withdraw

Every data subject has the right to withdraw consent to the processing of personal data at any time. The withdrawal is possible at any time without giving reasons and takes effect for the future.

i) Right to Complain

Every data subject has the right to lodge a complaint with the supervisory authority responsible for them if they are of the opinion that their personal data is not being processed in compliance with data protection law. The contact details of the supervisory authority responsible for us are:

Bavarian State Office for Data Protection Supervision

Promenade 27 (Schloss)

91522 Ansbach

Phone: +49 981 53 1300

Email: poststelle[at]lda.bayern.de

If you wish to exercise your rights as a data subject, please contact:

R. Scheuchl GmbH

Königbacher Straße 17

94496 Ortenburg

Phone: +49 8542 165-0

Email: datenschutz[at]scheuchl.de

Changes to the Privacy Policy

We reserve the right to change our privacy policies should this become necessary due to new technologies. Please ensure that you have the latest version. If fundamental changes are made to this privacy policy, we will announce these changes on our website.

Appointed Data Protection Officer

CB ADDATA GmbH

Office for Data Protection

Certified Data Protection Officer (DSB-TÜV) Christian Bößl

Reitmeierfeld 23

94099 Ruhstorf an der Rott

Phone: +49 8531 978447-0

Email: info[at]cb-addata.de

Status of the privacy policy: November 2019


Privacy Information for the RS.ERP Mobile App

Privacy Information for the Mobile App “RS.ERP”

R. Scheuchl GmbH · Verfahrenstechnik | Umweltschutz | Anlagenbau | Maschinenbau · www.scheuchl.de

This privacy information informs you pursuant to Art. 13 of the General Data Protection Regulation (GDPR) about the processing of personal data when using the mobile application “RS.ERP” (available for Android and iOS, hereinafter “app”). The app is an internal employee application of R. Scheuchl GmbH for time recording and operational processes.

It is intended exclusively for employees of R. Scheuchl GmbH and affiliated companies and cannot be used without an employee user account.

The privacy information of the website applies additionally to your visit to our website.

1. Controller

R. Scheuchl GmbH

Königbacher Straße 17

94496 Ortenburg

Phone: +49 8542 165-0

Email: datenschutz@scheuchl.de

2. Data Protection Officer

CB ADDATA GmbH

Christian Bößl

Reitmeierfeld 23

94099 Ruhstorf an der Rott

Phone: +49 8531 978447-0

3. Principles of Data Processing

The app contains no advertising and uses no analysis or tracking services.

There is no sale and no commercial disclosure of personal data to third parties.

All data transmissions between the app and company systems take place exclusively in encrypted form (TLS/HTTPS).

The processing of personal data takes place in the employment context on the basis of Art. 6(1)(b) GDPR in conjunction with Section 26(1) BDSG. For health data (Section 5.2), Section 26(3) BDSG applies; for the optional location function (Section 6), the basis is your explicit consent (Art. 6(1)(a) GDPR in conjunction with Section 26(2) BDSG).

No automated decisions within the meaning of Art. 22 GDPR are made; the app supports exclusively manual booking and administration processes.

Note: Insofar as a works agreement additionally regulates data processing in the app – in particular time recording, absence bookings and geofencing – this takes precedence. Copies are available on the notice board and from the works council.

4. Sign-In (Login)

4.1 Sign-In via Microsoft Entra ID (Standard Procedure)

Sign-in takes place via your company account using Microsoft Entra ID, including multi-factor authentication.

The provider is Microsoft Ireland Operations Ltd., One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland.

In doing so, Microsoft processes the data required for authentication (business email address, display name, sign-in time, device information) in accordance with the data processing agreements concluded between R. Scheuchl GmbH and Microsoft.

After successful sign-in, the app receives a session token with a limited period of validity, which is stored exclusively in encrypted form in the protected device memory. The token is irrevocably removed on sign-out.

4.2 Transitional Sign-In with Username and Password

As a transitional measure, a sign-in with a personal username and password against the internal ERP system is alternatively possible.

This function will be deactivated after the complete changeover to Microsoft Entra ID.

In this procedure too, transmission takes place exclusively in encrypted form (TLS/HTTPS); access data is not stored permanently on the device.

Legal basis (Sections 4.1 and 4.2): Art. 6(1)(b) GDPR in conjunction with Section 26(1) BDSG.

5. Time Recording, Project Times and Absence Bookings

5.1 General Time and Project Data

To fulfil the core function of the app, the system processes the following data:

  • Personnel number and name
  • Clock-in, clock-out and break bookings with time stamp
  • Home office bookings with time stamp (booking type “home office”)
  • Project time bookings (project, item, duration)
  • Business trip data (travel times, travel destination and country, expenses according to the BMF flat rates)

This data is transmitted to the internal company systems (time management/ERP) and stored there in accordance with the statutory retention periods of employment, tax and social insurance law. App-side technical booking logs are automatically and irrevocably deleted after 90 days.

Legal basis: Art. 6(1)(b) GDPR in conjunction with Section 26(1) BDSG (performance of the employment relationship as well as the statutory obligation to record working time pursuant to Section 3(2)(1) ArbSchG in conjunction with the case law of the Federal Labour Court).

5.2 Absence Type “Doctor”

The app enables the booking of the absence type “doctor” to record doctor’s visits during working hours. Since this indirectly logs the fact of a doctor’s visit, this booking type can constitute health data within the meaning of Art. 4(15) GDPR.

The processing takes place exclusively for the purposes of payroll accounting, the documentation of working time and compliance with labour law obligations. It is necessary in the employment context in order to fulfil rights and obligations arising from the employment relationship and is proportionate, taking your interests into account.

Legal basis: Art. 9(2)(b) GDPR in conjunction with Section 26(3) BDSG (processing of special categories of personal data in the employment context to fulfil rights and obligations arising from labour law).

Note: Insofar as you do not wish to use the “doctor” booking type, the general absence booking is available to you as an alternative. Please speak to your supervisor.

6. Location Data – Zone Identifier and Automatic Clocking / Geofencing

The time recording view of the app shows you whether your device is located inside or outside a defined plant area (e.g. “outside all zones”). This display serves exclusively for your own information and requires a one-off query of the device location by the operating system. The determined zone identifier is not transmitted to the company systems, provided that the automatic clocking function (Section 6.2) is not activated.

6.2 Automatic Clocking / Geofencing (Optional)

The app offers an optional function that automatically triggers a time booking when entering or leaving fixed defined plant areas.

Requirements and functioning:

The function is available exclusively for company areas enabled for this purpose and requires your explicit consent (location authorisation in the operating system, including background access). The check as to whether the device is located within a plant zone takes place entirely locally on your device. Raw GPS data and geo-coordinates are not transmitted to the company systems.

In the event of a zone event, only the triggered time booking together with the identifier of the relevant plant zone is transmitted. No movement profiles are created.

Withdrawal and deactivation:

You can deactivate the function at any time in the app via the setting “auto-clocking active” or withdraw the location authorisation in the operating system. Your withdrawal does not affect the lawfulness of the processing carried out up to that point. The app remains fully usable without location authorisation (manual clocking).

Legal basis: Art. 6(1)(a) GDPR in conjunction with Section 26(2) BDSG (consent).

7. Push Notifications and Messages (Optional)

For optional notifications – for example reminders about the order deadline for lunch, approval requests or vehicle appointments – the app uses the Firebase Cloud Messaging (FCM) service of Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland (as well as for the server-side infrastructure: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA).

In doing so, a pseudonymous, device-related token is generated by FCM and processed for the purpose of message delivery. Delivery may take place via servers in the USA. Incoming notifications are additionally stored with a time stamp in the messages area of the app and can be retrieved there.

Third-country transfer:

The transmission of personal data to the USA is based primarily on the adequacy decision of the European Commission on the EU-US Data Privacy Framework (Implementing Decision 2023/1795 of 10 July 2023). In addition, EU standard contractual clauses pursuant to Art. 46(2)(c) GDPR have been agreed with Google.

You can specifically deactivate individual notification categories in the app settings or switch off push notifications entirely via the system settings of your device. The device token is removed on sign-out as well as on uninstallation of the app.

Legal basis: Art. 6(1)(b) GDPR in conjunction with Section 26(1) BDSG (operational communication in the employment context).

8. Further Functions

8.1 Lunch Ordering

The app enables the ordering of lunch from the supplier “Da Kone” and further connected suppliers.

In doing so, the following data is processed:

  • Orders (dish, price, billing method, e.g. wage deduction)
  • Order history per employee (retrievable in the “my orders” area)

Only the aggregated collective order without personal reference (dish, quantity, notes) is transmitted to the food supplier. The personal order history remains exclusively in the internal company systems and is not visible to the supplier.

The order history is stored for the purposes of payroll accounting (wage deduction) and internal billing.

Legal basis: Art. 6(1)(b) GDPR in conjunction with Section 26(1) BDSG.

8.2 Vehicle Pool

The vehicle pool comprises the following functions:

Own bookings / reservations: Employees can reserve pool vehicles for their own trips and submit vehicle requests. In doing so, name, date, trip duration, destination, number of persons and project assignment are processed.

Dispatching: For authorised employees (dispatchers), an extended insight into the vehicle requests of other employees is available in order to allocate vehicles. In this view, the name of the requesting employee, travel destination, period, number of persons and customer assignment are displayed. Access is restricted to the employees responsible for dispatching.

Approval: Certain vehicle bookings go through an approval process. In doing so, booking details and approval decisions (approved / rejected) are logged with a time stamp.

All vehicle pool entries are processed exclusively internally. Entries are automatically deleted after 24 months.

Legal basis: Art. 6(1)(b) GDPR in conjunction with Section 26(1) BDSG.

8.3 Resource Requests (ReZu)

Requests and approval decisions (name, project, hours) are processed exclusively internally within the framework of the approval process.

Legal basis: Art. 6(1)(b) GDPR in conjunction with Section 26(1) BDSG.

9. Overview of App Permissions

Permission Purpose Required?
Internet Communication with the company systems Yes - mandatory
Location (foreground) Display of the current zone identifier in the time recording view No – optional, when using the zone view
Location (also in the background) Automatic clocking at plant zones (Section 6.2) No – optional, opt-in required
Notifications Receipt of push messages (Section 7) No - optional

10. Recipients and Third-Country Transfer

Recipient Purpose Place of processing
Internal systems of R. Scheuchl GmbH (ERP/time management) Processing of the booking and operational data Germany / EU
Microsoft Ireland Operations Ltd., Dublin, Ireland Sign-in and authentication (Section 4.1) EU / EEA
Google Ireland Ltd. / Google LLC (USA) Delivery of push notifications (Section 7) EU and USA (EU-US DPF / SCCs)
Food suppliers Aggregated collective order without personal reference (Section 8.1) Germany

No disclosure of personal data to third parties beyond this takes place.

11. Storage Period

Data category Storage period
Time, absence and billing data In accordance with the statutory retention periods (employment, tax and social insurance law; generally 6 or 10 years)
App-side technical booking logs 90 days, then automatic deletion
Order history (lunch) Until fulfilment of the billing purpose, then in accordance with the tax law retention periods
Vehicle pool entries 24 months, then automatic deletion
Push device token Until sign-out or uninstallation of the app
Session token on the device Until expiry of the session validity or until sign-out; storage exclusively in the encrypted device memory

12. Your Rights as a Data Subject

You have the following rights:

  • Access (Art. 15 GDPR): You can request information about the data stored about you.
  • Rectification (Art. 16 GDPR): You can request the rectification of incorrect data.
  • Erasure (Art. 17 GDPR): You can request the erasure of your data under the statutory conditions.
  • Restriction of processing (Art. 18 GDPR): You can request the restriction of processing under the statutory conditions.
  • Data portability (Art. 20 GDPR): You can request the release of your data in a structured, machine-readable format.
  • Objection (Art. 21 GDPR): You can object to the processing of your data on grounds relating to your particular situation, insofar as the processing is based on a legitimate interest.
  • Withdrawal of consent (Art. 7(3) GDPR): You can withdraw a granted consent – in particular for the location function – at any time with effect for the future, most easily directly in the app or operating system settings. The withdrawal does not affect the lawfulness of the processing carried out up to that point.

To exercise your rights, please contact:

R. Scheuchl GmbH

Königbacher Straße 17

94496 Ortenburg

Email: datenschutz@scheuchl.de

13. Right to Complain

You have the right to lodge a complaint with the competent data protection supervisory authority:

Bavarian State Office for Data Protection Supervision (BayLDA)

Promenade 27 (Schloss)

91522 Ansbach

Phone: +49 981 53 1300

Email: poststelle@lda.bayern.de

Website: www.lda.bayern.de

14. Changes to This Privacy Information

This privacy information is adapted when the functions of the app, the services used or the legal framework change substantially. The current version stored in the app and published here applies in each case. You will be informed separately of substantial changes.

Status: July 2026