Data protection according to the requirements of the GDPR (DSGVO)
Privacy Policy
Last updated: July 2026
In case of discrepancies between the German and English versions of this Privacy Policy, the German version shall prevail.
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) and other applicable data protection laws is:
Hagen® GmbH Planer und Architekten BDA
Geisseestraße 39
90439 Nuremberg
Germany
Tel.: +49 (0) 911 586 49-0
E-mail: info@hagen-architekten.de
Website: www.hagen-architekten.de
2. Data protection contact
For questions relating to data protection, you may contact our data protection contact:
Henri Hagen
c/o Hagen® GmbH Planer und Architekten BDA
Geisseestraße 39
90439 Nuremberg
Germany
Tel.: +49 (0) 911 586 49-0
E-mail: info@hagen-architekten.de
3. General information on data processing
We process personal data only to the extent necessary to provide a functional website, respond to enquiries, carry out pre-contractual or contractual measures, comply with legal obligations or safeguard legitimate interests. Processing based on consent takes place only where such consent has been given.
Personal data means any information relating to an identified or identifiable natural person, in particular names, contact details, communication content, usage data, IP addresses or other online identifiers.
Where we use service providers that process personal data on our behalf, this is done on the basis of data processing agreements pursuant to Art. 28 GDPR, where legally required.
4. Legal bases for processing
Where we obtain consent, the legal basis is Art. 6(1)(a) GDPR.
Where processing is necessary for the performance of a contract or in order to take steps prior to entering into a contract, the legal basis is Art. 6(1)(b) GDPR.
Where processing is necessary for compliance with a legal obligation, the legal basis is Art. 6(1)(c) GDPR.
Where processing is necessary for the purposes of legitimate interests pursued by us or by a third party, and the interests or fundamental rights and freedoms of the data subject do not override those interests, the legal basis is Art. 6(1)(f) GDPR.
For storing information on users’ terminal equipment or accessing information already stored on such equipment, the requirements of Section 25 TDDDG also apply. Where consent is required, storage or access is based on Section 25(1) TDDDG. Where storage or access is strictly necessary for technical reasons, it is based on Section 25(2) TDDDG.
5. Hosting, technical provision of the website and server log files
When our website is accessed, technically necessary data is processed by the web server in order to provide the website, ensure system security and analyse technical issues.
This may include in particular:
– IP address
– date and time of access
– requested URL or file
– referrer URL
– browser type and browser version
– operating system used
– hostname of the accessing computer
– amount of data transferred
– HTTP status code
– requesting internet service provider
Processing is carried out for the technical provision of the website, to ensure the stability and security of our IT systems and to detect misuse and attacks.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure and functional operation of our website.
Server log files are generally stored only for as long as necessary for the above purposes. Longer storage may take place where this is required to investigate security incidents, defend against attacks or establish, exercise or defend legal claims.
6. Cookies and similar technologies
Our website uses cookies and similar technologies. Cookies are small text files that may be stored on the user’s terminal device. Similar technologies may include local storage, session storage, pixels, tags or other technical identifiers.
We distinguish in particular between:
– technically necessary cookies and technologies,
– statistics and analytics cookies,
– cookies and technologies of external media and services.
Technically necessary cookies and technologies are used to provide basic website functions, such as language settings, consent settings, security functions or technical website delivery. The legal basis for access to the terminal device is Section 25(2) TDDDG. Subsequent processing of personal data is based on Art. 6(1)(f) GDPR, unless another legal basis applies.
Non-technically necessary cookies and technologies, in particular for analytics, statistics, external media or similar services, are used only with prior consent. The legal basis is Section 25(1) TDDDG in conjunction with Art. 6(1)(a) GDPR.
You may withdraw or change your consent at any time with effect for the future by reopening the cookie or privacy settings of our website. You may also delete or block cookies through your browser settings. If cookies are disabled, the functionality of the website may be limited.
7. Consent management / cookie settings
We use a consent management system on our website in order to obtain, document and manage consents for cookies and external services.
The following data may be processed in particular:
– consents and refusals selected
– time of consent
– technical information about the device and browser used
– IP address in shortened or otherwise minimised form
– consent ID or similar identifier
Processing is carried out in order to prove consent given or refused and to technically implement the selected settings.
The legal basis is Art. 6(1)(c) GDPR where processing is necessary to comply with legal documentation obligations, and Art. 6(1)(f) GDPR. Our legitimate interest lies in the legally compliant management of consents and privacy settings. Where information is stored on or read from the terminal device, this is carried out for technically necessary purposes on the basis of Section 25(2) TDDDG.
The data is stored for as long as necessary to document consent and manage the settings.
8. Contact by e-mail
If you contact us by e-mail, we process the personal data transmitted by you. This may include in particular:
– name
– e-mail address
– telephone number, if provided
– company or organisation, if provided
– content of the message
– date and time of communication
– technical metadata of the e-mail communication
The data is processed in order to handle your enquiry and communicate with you.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in handling and responding to your enquiry. If your enquiry is aimed at entering into or performing a contract, Art. 6(1)(b) GDPR is an additional legal basis. Where statutory retention obligations apply, the legal basis is Art. 6(1)(c) GDPR.
The data will be deleted once it is no longer required to handle the enquiry and no statutory retention obligations or legitimate interests justify further storage.
9. Contact form / Contact Form 7
Our website may use contact forms that are technically provided through the WordPress plugin Contact Form 7.
If you use a contact form, we process the data that you enter in the respective form. This may include in particular:
– name
– e-mail address
– telephone number
– company or organisation
– subject
– message text
– any further information requested in the form
– time of submission
– technical connection data, in particular IP address and browser information, where necessary for security and misuse prevention
Processing is carried out to handle your enquiry, communicate with you and prevent misuse of our forms.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in processing the enquiry and protecting the website against misuse. If the enquiry is aimed at entering into or performing a contract, Art. 6(1)(b) GDPR is an additional legal basis.
Data transmitted via the contact form will be deleted once it is no longer required to handle the enquiry and no statutory retention obligations or legitimate interests justify further storage.
10. Sending website e-mails / WP Mail SMTP
We may use the WordPress plugin WP Mail SMTP to ensure the reliable technical delivery of e-mails triggered through our website. The plugin is used to technically send e-mails via a configured e-mail or SMTP service.
The following data may be processed in particular:
– sender and recipient address
– subject
– message content
– time of dispatch
– technical dispatch and delivery information
Processing is carried out to ensure the reliable delivery of contact, system or notification e-mails.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in secure and reliable e-mail communication. Where the communication serves pre-contractual or contractual purposes, Art. 6(1)(b) GDPR is an additional legal basis.
Where external e-mail or IT service providers are used, processing is carried out on the basis of appropriate contractual arrangements, where legally required.
11. Applications and careers section
If you apply to us, we process the personal data that you submit as part of your application. This may be done by e-mail, through an application form or through an application solution embedded on the website.
The following data may be processed in particular:
– name and contact details
– address
– date of birth, if provided
– application documents, in particular cover letter, CV, certificates and work samples
– information on education, professional background, qualifications and skills
– communication content
– technical transmission data
Processing is carried out to conduct the application process and decide whether to establish an employment relationship.
The legal basis is Section 26 BDSG in conjunction with Art. 6(1)(b) GDPR. Where you provide consent, for example for inclusion in an applicant pool, the legal basis is Art. 6(1)(a) GDPR.
We may use internal applications or external IT service providers, in particular application or recruiting solutions such as HireZoot, for the technical management of applications. Where service providers process personal data on our behalf, this is done on the basis of data processing agreements pursuant to Art. 28 GDPR, where required.
Application data is generally deleted once it is no longer required for the decision on the application, but no later than after expiry of appropriate retention periods, unless consent has been given for longer storage or statutory retention obligations or legitimate interests justify longer storage. In the event of a successful application, the data may be transferred to the personnel file.
12. Akismet Anti-Spam
We may use the Akismet Anti-Spam service on our website to protect contact forms, comments or other input functions against spam, misuse and automated attacks.
The provider is Automattic Inc., 60 29th Street #343, San Francisco, CA 94110, USA.
The following data may be processed in particular:
– IP address
– user agent or browser information
– referrer
– submitted form or comment content
– name, e-mail address and website, if entered
– time of submission
– technical verification data for spam detection
The data may be transmitted to Automattic servers and processed there for spam checking.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in protecting our website, IT systems and communication channels against spam, misuse and automated attacks.
Where the service stores information on your terminal device or accesses information stored there and this is not strictly technically necessary, this is done only on the basis of your consent pursuant to Section 25(1) TDDDG in conjunction with Art. 6(1)(a) GDPR.
A transfer to third countries, in particular the USA, cannot be excluded. Such transfer takes place only where there is an appropriate legal basis, in particular an adequacy decision, appropriate safeguards pursuant to Art. 46 GDPR or a statutory exception.
13. Wordfence Security
We use the Wordfence Security plugin on our website to protect the website against attacks, malware, brute-force attacks, unauthorised access and other security risks.
The provider is Defiant, Inc., 800 5th Avenue, Suite 4100, Seattle, WA 98104, USA.
The following data may be processed in particular:
– IP address
– accessed URLs
– date and time of access
– browser and device information
– referrer
– information on login attempts
– security-related events
– technical data for attack detection and firewall functionality
Processing is carried out to secure the website, detect and defend against attacks and ensure the integrity and availability of our IT systems.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure operation of the website and protection against abusive or harmful access.
Within the scope of the security functions, data may be transmitted to Defiant, Inc. A transfer to third countries, in particular the USA, cannot be excluded. Such transfer takes place only where there is an appropriate legal basis, in particular an adequacy decision, appropriate safeguards pursuant to Art. 46 GDPR or a statutory exception.
Security-related data is stored only for as long as necessary to detect, defend against and document security risks.
14. Google Analytics / Google Site Kit
We use Google Analytics, a web analytics service provided by Google, which may be integrated into our website in particular via the WordPress plugin Site Kit by Google.
The provider for users in the European Economic Area is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The parent company is Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
Google Analytics enables us to statistically evaluate the use of our website and improve our information offering. The following data may be processed in particular:
– pages accessed
– duration of visit
– interactions on the website
– referrer
– approximate location
– browser and device information
– screen resolution
– language settings
– IP address, usually in shortened or otherwise minimised form
– cookie or similar online identifiers
Google Analytics may use cookies or similar technologies. The integration takes place only after your consent.
The legal basis for storing information on your terminal device or accessing information already stored there is Section 25(1) TDDDG. The legal basis for the subsequent processing of personal data is Art. 6(1)(a) GDPR.
You may withdraw your consent at any time with effect for the future via the cookie or privacy settings of our website.
The retention period for data processed in Google Analytics depends on the settings configured in Google Analytics. User and event data is generally deleted after expiry of the retention period selected by us. Google Analytics cookies may be stored for up to two years, depending on the specific setting and cookie used, unless you delete them earlier or withdraw your consent.
Google may also process personal data on servers outside the European Union or the European Economic Area, in particular in the USA. Such transfer takes place only where there is an appropriate legal basis, in particular an adequacy decision, appropriate safeguards pursuant to Art. 46 GDPR or a statutory exception.
15. Google Fonts / Google Webfonts
Our website uses web fonts for the uniform display of fonts. These may be provided locally on our server or, where technically integrated, loaded from Google servers.
The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The parent company is Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
If fonts are loaded from Google servers, the user’s browser establishes a connection to Google. In this process, in particular the IP address, browser information, technical device information and the page accessed may be transmitted to Google.
Processing is carried out for the uniform, technically stable and visually consistent display of our website.
Where fonts are integrated locally, no connection to Google servers takes place in this respect. Where fonts are loaded externally from Google and consent is required for this, the integration is based on Section 25(1) TDDDG in conjunction with Art. 6(1)(a) GDPR. Otherwise, processing is based on Art. 6(1)(f) GDPR. Our legitimate interest lies in the uniform display and technical functionality of the website.
Google may also process personal data outside the European Union or the European Economic Area, in particular in the USA. Such transfer takes place only where there is an appropriate legal basis.
16. Google Maps
Our website may integrate map material from Google Maps.
The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The parent company is Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
If you access a page with embedded Google Maps or activate the map function, data may be transmitted to Google. This may include in particular:
– IP address
– location data, where enabled by the user
– browser and device information
– date and time of access
– page accessed
– interactions with the map
Google Maps is used to display locations, directions and map information in a user-friendly way.
The integration generally takes place only after your consent. The legal basis for storing information on your terminal device or accessing information already stored there is Section 25(1) TDDDG. The legal basis for the subsequent processing of personal data is Art. 6(1)(a) GDPR.
You may withdraw your consent at any time with effect for the future via the cookie or privacy settings of our website.
Google may also process personal data outside the European Union or the European Economic Area, in particular in the USA. Such transfer takes place only where there is an appropriate legal basis.
17. YouTube
Our website may embed videos from YouTube.
The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The parent company is Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
If you activate an embedded YouTube video or access a page with active YouTube content, data may be transmitted to Google. This may include in particular:
– IP address
– browser and device information
– date and time of access
– page accessed
– referrer
– playback and interaction data
– cookie or similar online identifiers
Where possible, we embed YouTube content in a privacy-friendly manner, for example through a prior consent request or a two-click solution. However, data may be transmitted to Google at the latest when the video is activated.
The integration generally takes place only after your consent. The legal basis for storing information on your terminal device or accessing information already stored there is Section 25(1) TDDDG. The legal basis for the subsequent processing of personal data is Art. 6(1)(a) GDPR.
You may withdraw your consent at any time with effect for the future via the cookie or privacy settings of our website.
Google may also process personal data outside the European Union or the European Economic Area, in particular in the USA. Such transfer takes place only where there is an appropriate legal basis.
18. Business development and B2B contact data
For business development and the maintenance of business contacts, we process personal data of contact persons at potential, existing or former commercial clients, business partners and other professional contacts.
This may include in particular:
– name
– function and professional position
– employer or company
– business e-mail address
– business telephone number
– business address
– area of responsibility
– publicly available company and contact information
– communication content and notes in a business context
The data is obtained either from direct communication with the data subject, from existing business relationships, from publicly available sources such as company websites, professional networks, public registers or from third-party referrals in a business context.
Processing is carried out to initiate, perform and maintain business relationships in a commercial context, for project acquisition, for communication with potential or existing clients and business partners and for the internal organisation of business development.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in business development, maintaining professional contacts and directly approaching potential commercial clients and business partners in the B2B sector. Where processing is aimed at entering into or performing a contract, Art. 6(1)(b) GDPR may also apply.
Promotional contact is made only where permitted under the applicable data protection and competition law requirements. Data subjects may object at any time with effect for the future to the processing of their personal data for direct marketing purposes.
We may use internal IT applications and service providers to manage this contact data. Where service providers process personal data on our behalf, this is done on the basis of data processing agreements pursuant to Art. 28 GDPR, where legally required.
The data will be deleted once it is no longer required for the above purposes and no statutory retention obligations or legitimate interests justify further storage.
19. Recipients and categories of recipients
Personal data is transmitted to third parties only where this is necessary for the purposes described, where there is a legal obligation, where consent has been given or where another legal basis permits the transfer.
Recipients or categories of recipients may include in particular:
– hosting and IT service providers
– web and maintenance service providers
– e-mail and communication service providers
– providers of analytics, maps, media and security services
– providers of application or recruiting solutions
– tax advisers, lawyers and other professional advisers
– authorities, courts or other public bodies where legally required
Personal data is not disclosed to unrelated third parties for their own advertising purposes.
20. Transfers to third countries
In connection with the operation of our website and the services used, processing of personal data outside the European Union or the European Economic Area cannot be excluded, in particular in the USA.
A transfer to third countries takes place only where there is an appropriate legal basis. This may include in particular:
– an adequacy decision of the European Commission,
– appropriate safeguards pursuant to Art. 46 GDPR, in particular EU Standard Contractual Clauses,
– explicit consent,
– or a statutory exception pursuant to Art. 49 GDPR.
Where providers are certified under an adequacy decision, the transfer may be based on that adequacy decision. Otherwise, appropriate safeguards are agreed where required.
21. Storage period
We store personal data only for as long as necessary for the respective processing purposes, while consent exists or where statutory retention obligations or legitimate interests justify further storage.
Statutory retention periods may arise in particular from commercial and tax law provisions. Where data is no longer required for its original purposes but is subject to statutory retention obligations, processing will be restricted accordingly.
After the processing purpose ceases to apply and any retention periods have expired, the data will be deleted or anonymised.
22. Your rights as a data subject
If personal data relating to you is processed, you have the following rights under the GDPR:
a) Right of access
You have the right to obtain confirmation as to whether we process personal data concerning you. If this is the case, you have the right to access this personal data and the further information pursuant to Art. 15 GDPR.
b) Right to rectification
You have the right to request the rectification of inaccurate personal data and the completion of incomplete personal data pursuant to Art. 16 GDPR.
c) Right to erasure
Subject to the requirements of Art. 17 GDPR, you have the right to request the erasure of your personal data, in particular where the data is no longer necessary for the purposes for which it was collected or where you have withdrawn consent.
d) Right to restriction of processing
Subject to the requirements of Art. 18 GDPR, you have the right to request restriction of the processing of your personal data.
e) Right to data portability
Subject to the requirements of Art. 20 GDPR, you have the right to receive personal data that you have provided to us in a structured, commonly used and machine-readable format or to request transmission to another controller.
f) Right to withdraw consent
You have the right to withdraw consent at any time with effect for the future. The lawfulness of processing carried out before withdrawal remains unaffected.
g) Right to object
Subject to Art. 21 GDPR, you have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data based on Art. 6(1)(e) or Art. 6(1)(f) GDPR.
Where personal data is processed for direct marketing purposes, you have the right to object at any time to the processing of your personal data for such marketing. This also applies to profiling to the extent that it is related to such direct marketing.
h) Automated individual decision-making, including profiling
You have the right not to be subject to a decision based solely on automated processing that produces legal effects concerning you or similarly significantly affects you. We do not carry out such automated decision-making.
23. Right to lodge a complaint with a supervisory authority
You have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data violates data protection law.
You may contact in particular the supervisory authority of your habitual residence, place of work or the place of the alleged infringement.
The authority generally responsible for us is:
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18
91522 Ansbach
Germany
E-mail: poststelle@lda.bayern.de
Website: www.lda.bayern.de
24. Updates and amendments to this Privacy Policy
We reserve the right to amend this Privacy Policy if the legal situation, our website, the services used or our data processing procedures change. The current version published on our website applies.