Purchasing and invoice processing

Data protection information in accordance with Article 13 (1) and (2) of the General Data Protection Regulation (GDPR ) on purchasing and invoice processing at the Zittau/Görlitz University of Applied Sciences (HSZG).

Person responsible for data processing

Zittau/Görlitz University of Applied Sciences
Theodor-Körner-Allee 16
02763 Zittau

Please send inquiries regarding data processing to
Your request will be forwarded to the responsible department and processed promptly.

Data protection officer of the controller

The data protection officer can be contacted at

DID Dresdner Institut für Datenschutz
Hospitalstraße 4
01097 Dresden

Web.: www.dids.de
Tel.: +49 (0)351 / 655 772 - 0
E-Mail:

Purposes of data processing

The HSZG processes personal tender, order and invoice data for the purposes of tender evaluation, preparation of decisions under public procurement law, triggering of orders and for checking and settlement of invoices.

Legal basis

Personal data is processed on the basis of Art. 6 para. 1 lit. b, e GDPR
in conjunction with § 3 SächsDSDG, § 6 para. 3 VOL/A, § 3 SächsVergabeG and §§ 33, 34, 48 VgV .

Categories of personal data

The HSZG processes the following personal data for the purposes of this processing activity:

  • First name, surname
  • Address and contact details
  • Offer data
  • contract data
  • invoice data
  • handwritten signature
  • Bank details
  • E-mail data for e-mail invoice receipt
  • Information about subcontractors
  • Commercial register excerpt
  • Business registration
  • Data from self-declaration as proof of suitability of applicants and bidders, e.g:
    • Company turnover for the last three completed financial years
    • Reference provider for the execution of comparable services
    • Annual average number of employees in completed financial years by professional group
    • Number of employees for the provision of the contracted services by occupational group
    • Competent Chamber of Skilled Crafts with registration number and registration date

Data collection from third parties, in accordance with Art. 4 No. 10 GDPR:

  • Prequalification bodies (publicly accessible or sometimes for details of the bidder)
  • Federal Office of Justice (central trade register)

Receiver

The personal data is regularly processed by employees of HSZG for the purposes of this data processing. The data is disclosed to the main cash office in Saxony.

The HSZG does not transfer personal data to a third country or an international organization.

Storage duration

The retention period for personal data is generally 10 years. In individual cases, however, it can be up to 30 years.

Rights of the data subjects

As a person affected by the processing of your personal data, you have the following rights if the legal requirements are met.

  • You have the right to information about the processing of your personal data(Art. 15 GDPR).
  • You have the right to rectification of inaccurate personal data concerning you (Art.16 GDPR)
  • You have the right to erasure of your personal data (Art.17 GDPR).
  • You have the right to request the restriction of the processing of your personal data (Art.18 GDPR)
  • You have the right to data portability of your personal data (Art.20 GDPR)
  • You have the right to object to the processing of your personal data at any time (Art.21 GDPR)
  • You have the right to withdraw your consent to data processing at any time. The lawfulness of the data processing carried out on the basis of your consent until revocation remains unaffected(Art. 13 para. 2 lit. c GDPR).
  • You have the right to lodge a complaint with the Saxon data protection officer
    (Art. 77 GDPR).

Provision of personal data

The provision of personal data is required in accordance with Art. 13 para. 2 lit. e GDPR for the implementation of pre-contractual measures and fulfillment of resulting contractual obligations. If the personal offer, order and invoice data is not provided, it cannot be taken into account in the award procedure, no order of goods or services and no payment of invoice amounts can be made.

Decision-making and profiling

This processing activity does not involve automated decision-making or profiling in accordance with
Art. 22 GDPR.