This is a convenience translation. The legally binding version is the German privacy policy.
Draft pursuant to the GDPR (DSGVO). Because of the sensitive data involved (passport, training, employment, financing), the final version should be reviewed before going live by a recognised generator or a lawyer.
[Name of the owner], AUREA GLOBAL, [address], info@aureaglobal.de.
We process personal data only insofar as it is necessary for the provision of our services, and on the basis of the GDPR. Your data is treated confidentially.
When the website is accessed, technical access data (e.g. IP address, time, page accessed) is processed by the hosting provider. The legal basis is the legitimate interest in secure operation (Art. 6 (1) (f) GDPR). [Enter the hosting provider; name the data processing agreement if one exists.]
If you contact us via the form, by email or by phone, we process your details in order to handle your enquiry (Art. 6 (1) (b) and (f) GDPR). The data is deleted as soon as it is no longer required and no retention obligations prevent this. [If the form is processed via an external service, name the service.]
In the event of an engagement, we process the data required for the procedure, including special categories and sensitive documents (e.g. passport, birth and civil-status data, training, employment, social-insurance history, certificate of good conduct, proof of financing). The legal basis is contract and consent (Art. 6 (1) (b) and (a), and where applicable Art. 9 (2) (a) GDPR). Transfer to employers, authorities, recognition bodies, foreign missions and commissioned translators takes place only insofar as required for the procedure and covered by consent.
We store data only for as long as it is required for the purposes or for as long as statutory retention periods apply. [Add specific periods following legal review.]
You have the right to access, rectification, erasure, restriction, data portability and objection, as well as the right to withdraw consent that has been given. You may lodge a complaint with a data protection supervisory authority.
[List whether and which service providers or recipients receive data.] Important: as things currently stand, Türkiye does not have an adequacy decision from the EU Commission. A transfer of personal data to Türkiye is therefore only permissible with appropriate safeguards under Art. 46 GDPR (in practice, EU Standard Contractual Clauses, where applicable with a Transfer Impact Assessment) or on the basis of explicit, informed consent under Art. 49 GDPR. State any such transfer transparently here.
[Complete only if used. For consent-requiring cookies or tracking, implement a consent banner.]
Still to be clarified before going live: name the hosting provider and form service specifically, properly govern third-country transfers (in particular to Türkiye), define specific storage and deletion periods, and have the overall version reviewed by a generator or a lawyer.