1. Data controller
The data controller responsible for the processing of personal data on this website is:
Fachkraft Ausland GmbH
Taunusanlage 8
60329 Frankfurt am Main, Germany
Email: hello@fachkraft-ausland.de
Phone: +49 69 1234 5678
2. What data we collect
Depending on how you interact with us, we may collect the following categories of personal data:
Contact form & candidate applications
- Full name, email address, phone number
- Country of residence and nationality
- Profession, qualifications, German language level
- CV / résumé and supporting documents (when uploaded)
- Free-text message content
Employer enquiries
- Company name, role of contact person, business email and phone
- Hiring needs and role descriptions
Automatically collected technical data
- IP address (truncated where technically possible)
- Browser type, language and operating system
- Pages viewed, referring URL, timestamps
- Device type (mobile / desktop)
3. Legal basis for processing
We process personal data under the following lawful bases of the GDPR:
| Activity | Legal basis (GDPR Art.) |
|---|---|
| Contact form & candidate intake | Art. 6(1)(b) — pre-contractual measures |
| Visa & recruitment service delivery | Art. 6(1)(b) — contract performance |
| Newsletter subscription | Art. 6(1)(a) — consent |
| Cookies & analytics | Art. 6(1)(a) — consent / Art. 6(1)(f) — legitimate interest |
| Legal record-keeping | Art. 6(1)(c) — legal obligation |
| Sensitive data (health, qualifications) | Art. 9(2)(a) — explicit consent |
4. Purpose of processing
We use your data only for the purposes you submit it for, namely:
- Assessing your eligibility for German work visas
- Matching you with German employers in our partner network
- Filing visa, Blue Card and Chancenkarte applications on your behalf
- Coordinating relocation logistics (housing, banking, insurance)
- Providing post-arrival integration support
- Sending you optional newsletter updates (only with your consent)
5. Sharing with third parties
We share personal data only with carefully selected processors and only when necessary to deliver our services. All processors are bound by Data Processing Agreements (DPAs) under Art. 28 GDPR.
- German employers — only after your explicit written consent and only for the role you applied to
- German immigration authorities (Ausländerbehörde, ZAV) — for visa filings
- Recognition offices (ZAB, IHK) — for credential recognition
- Cloud hosting providers within the EU — for data storage
- Email providers — for transactional communication only
We never sell or rent your data to advertisers or data brokers.
6. Storage & retention
We store personal data only as long as necessary for the purposes set out above:
- Contact form submissions (no follow-up)
- Deleted after 90 days
- Active candidate files
- Stored for the duration of the engagement + 6 months post-arrival support
- Placed candidates (legal record-keeping)
- 10 years (in line with §147 AO and §257 HGB)
- Newsletter subscribers
- Until you unsubscribe; opt-out link included in every email
- Server log files
- Maximum 14 days, then automatically deleted
All data is hosted on servers physically located within the European Union.
7. Your rights under the GDPR
As a data subject under the GDPR, you have the following rights at any time:
- Right of access (Art. 15) — request a copy of all data we hold on you
- Right to rectification (Art. 16) — correct inaccurate data
- Right to erasure (Art. 17) — "right to be forgotten"
- Right to restriction (Art. 18) — limit how we process your data
- Right to data portability (Art. 20) — receive your data in a machine-readable format
- Right to object (Art. 21) — to processing based on legitimate interest
- Right to withdraw consent (Art. 7) — at any time, without affecting prior lawfulness
- Right to lodge a complaint — with the Hessian Data Protection Authority (Hessischer Beauftragter für Datenschutz und Informationsfreiheit)
To exercise any of these rights, contact our DPO using the details in section 10.
8. Cookies & tracking
This website uses a minimal set of cookies and browser storage:
| Name | Purpose | Type | Lifetime |
|---|---|---|---|
fka_lang | Stores your selected language (EN / DE) | Strictly necessary | 1 year |
fka-theme | Stores your light / dark mode preference | Strictly necessary | localStorage |
fka-cookie-consent | Stores your cookie consent decision | Strictly necessary | localStorage |
session | Flask session for form CSRF | Strictly necessary | Session |
Strictly necessary cookies do not require consent under §25(2) TTDSG. We do not use third-party analytics (no Google Analytics, no Facebook Pixel, no advertising trackers) by default. Should we ever introduce optional analytics, we will request your explicit opt-in consent first.
9. Security measures
We implement appropriate technical and organisational measures (TOMs) under Art. 32 GDPR to protect your data:
- TLS 1.3 encryption for all data in transit
- Encrypted storage at rest (AES-256)
- Role-based access control with least-privilege principle
- Regular security audits and penetration testing
- Mandatory two-factor authentication for all internal access
- EU-only data processing and storage
- Documented incident response and breach notification procedure (Art. 33)
10. Contact our Data Protection Officer
For any questions about this privacy policy, or to exercise your rights, contact our Data Protection Officer:
Data Protection Officer
Fachkraft Ausland GmbH
Taunusanlage 8, 60329 Frankfurt am Main
Email: dpo@fachkraft-ausland.de
You also have the right to lodge a complaint directly with the supervisory authority:
Hessischer Beauftragter für Datenschutz und Informationsfreiheit
Postfach 3163, 65021 Wiesbaden
datenschutz.hessen.de