Privacy Policy

Privacy Policy — Ferienjob Germany
🔒 Data Protection

Privacy Policy

Information on the processing of your personal data pursuant to Art. 13 and 14 GDPR (EU General Data Protection Regulation / Datenschutz-Grundverordnung — DSGVO)

🏢 SHB Personalservice GmbH 📅 Last updated: 26.08.2026 ⚖️ GDPR compliant
🏢
Section 1
Controller (Art. 4 No. 7 GDPR)

The controller responsible for the processing of your personal data within the meaning of the EU General Data Protection Regulation (GDPR) is:

CompanySHB Personalservice GmbH
AddressStockholmer Platz 1, 70173 Stuttgart, Germany
DirectorRon Waldkönig
RegisterHRB 790619, Amtsgericht Stuttgart (Local Court Stuttgart)
ℹ️ No Data Protection Officer appointed SHB Personalservice GmbH is not currently required to appoint a Data Protection Officer (DPO). For all data protection enquiries, please contact us directly at the email address above.
📋
Section 2
Personal Data Collected & Purposes of Processing

We process personal data exclusively for the purposes set out in this Privacy Policy. The following categories of data are collected and processed in connection with the Ferienjob Germany programme:

Data CategorySpecific DataPurposeLegal Basis
Identity Data First name, last name, birth name, date of birth, place of birth, gender, nationality, passport number, passport status Identification, work permit application (ZAV), visa application Art. 6(1)(b) GDPR
Contact Data Email address, WhatsApp number, home address (street, postcode, city, region, country) Communication, programme coordination, emergency contact Art. 6(1)(b) GDPR
Academic Data University, field of study, expected graduation date, semester break dates, enrolment status Verification of eligibility, ZAV application Art. 6(1)(b) GDPR
Application Documents Passport copy, student ID, Immatrikulationsbescheinigung (enrolment certificate), enrollment certificate, CV, academic calendar, police clearance certificate, proof of health insurance, certificate of residence Application processing, ZAV work permit application, visa application Art. 6(1)(b) GDPR
Visa & Permit Data Visa appointment date, tracking number, visa validity period, visa scans, work permit (ZAV), permit validity period Programme administration, status tracking, employer obligations Art. 6(1)(b) GDPR / Art. 6(1)(c) GDPR
Travel Data Arrival/departure dates and times, airport, flight ticket, travel insurance certificate Arrival coordination, accommodation planning, on-site support Art. 6(1)(b) GDPR
Bank Details IBAN, BIC, name of bank Salary payment by the employer (Abax) Art. 6(1)(b) GDPR
Body Measurements T-shirt size, shoe size, trouser size Provision of personal protective equipment and work clothing Art. 6(1)(b) GDPR
Language Skills English proficiency level, German proficiency level Assignment planning, matching with placement sites Art. 6(1)(b) GDPR
T&C Acceptance Confirmation of Programme Terms (timestamp, full name, IP address, user agent, version) Evidence of consent, legal compliance Art. 6(1)(c) GDPR
Technical Data IP address, browser type, operating system, page views, session duration (if analytics are used) Website operation and security Art. 6(1)(f) GDPR
Communication Data Email correspondence, WhatsApp messages (programme-related), contact form submissions Participant support, programme coordination Art. 6(1)(b) GDPR

Interview scheduling

If we invite you to an online interview, we process the proposed and confirmed appointment slots, your confirmation and the meeting link assigned to you. This data is used solely to arrange and conduct the interview and to update your application status (Art. 6(1)(b) GDPR).

Weekly advance payment request

While you are employed in Germany, we ask you once per week via your dashboard whether you wish to receive the weekly advance payment. We store your yes or no response and its timestamp to process the payment through your employer (Art. 6(1)(b) GDPR).
⚖️
Section 3
Legal Bases for Processing

We process your personal data on the following legal bases pursuant to Art. 6 GDPR:

📄 Art. 6(1)(a) — Consent
For the sending of information about future Ferienjob programmes and job opportunities, where you have given your explicit prior consent.
📋 Art. 6(1)(b) — Contract Performance
Primary legal basis: Processing necessary for the performance of the application process, programme participation, and employment relationship (pre-contractual and contractual measures).
🏛️ Art. 6(1)(c) — Legal Obligation
Transfer to the ZAV (Federal Employment Agency) for the work permit application; tax and social insurance obligations under German law.
⚡ Art. 6(1)(f) — Legitimate Interests
Website operation and security, fraud prevention, statistical analysis to improve our services, enforcement of legal claims.
⚠️ Right to Withdraw Consent (Art. 7 GDPR) Where we process your data on the basis of consent, you may withdraw that consent at any time with effect for the future — without giving reasons. The lawfulness of processing carried out prior to withdrawal remains unaffected. To withdraw consent, please email: datenschutz@ferienjobgermany.de
🤝
Section 4
Recipients & Transfer of Personal Data

We only transfer your data where this is necessary for the operation of the Ferienjob programme, required by law, or where you have consented. Specifically:

RecipientData TransferredLegal Basis / Purpose
Zentrale Auslands- und Fachvermittlung (ZAV)
Federal Employment Agency, Germany
Identity data, academic data, application documents, passport data, semester break dates Legally required work permit application under § 14 para. 2 BeschV (Art. 6(1)(c) GDPR)
Abax Personaldienstleistungen GmbH
Mannheim, Germany (Employer)
Identity data, contact data, application documents (incl. passport copy, police clearance certificate, enrolment certificate, CV), bank details, body measurements, language skills, visa/permit data, travel data Contract performance: establishment and execution of the employment relationship, payroll (Art. 6(1)(b) GDPR)
Placement Sites (Einsatzbetriebe)
Companies where students are deployed (logistics, production, hospitality, etc.)
Name, arrival data, contact information, language skills, body measurements (for work clothing), permit validity period Contract performance: deployment planning and coordination, required operational onboarding (Art. 6(1)(b) GDPR). Only the data strictly necessary for each placement is shared.
German Embassies / Consulates
In the participant's home country
Work permit documents and ZAV approval letter (presented by the participant personally at the visa appointment) Visa application: The participant submits documents directly. SHB does not transmit data to embassies directly.
Processors (IT / Infrastructure)
Hosting, WordPress, email, security (details in Section 7)
Depending on the service: all data processed on the website. The security service additionally receives IP addresses of attack attempts. Data processing agreement (DPA) pursuant to Art. 28 GDPR concluded or in preparation
ℹ️ No disclosure to unspecified third parties Your personal data will not be disclosed to any third parties not listed in this Privacy Policy — except where required by law or with your explicit consent.
🌍
Section 5
Transfers to Third Countries (Art. 44 et seq. GDPR)

Some services we use process data in countries outside the European Union (EU) and the European Economic Area (EEA). We ensure that an adequate level of data protection is maintained in all such cases:

ServiceCountrySafeguard
Botpress Canada (Botpress Inc.) EU Standard Contractual Clauses (SCC). Canada holds an EU adequacy decision for commercial transfers.
Google (Push, Fonts)USA / IrelandEU-US Data Privacy Framework; notification content is encrypted and cannot be read by the push service.
Apple / Mozilla (Push)USADelivery of encrypted push notifications; EU Standard Contractual Clauses.
Defiant Inc. (Wordfence)USAOnly IP addresses of detected attack attempts; EU Standard Contractual Clauses.
Cloudflare Inc. (cdnjs)USADelivery of script libraries; EU-US Data Privacy Framework.
Meta (WhatsApp)Ireland / USAEU Standard Contractual Clauses.
⚠️ Note on US-based services Despite existing safeguards, US authorities may in certain circumstances obtain access to data processed by US companies. We take all available technical and organisational measures to minimise this risk and only use US-based services where necessary for the operation of the programme and where no equivalent EU alternative is available.
⏱️
Section 6
Retention Periods & Deletion

We retain your personal data only for as long as necessary for the respective processing purpose or as required by statutory retention obligations.

Data CategoryRetention PeriodReason
Application and programme documents 10 years after programme end Commercial law retention obligation (§ 257 HGB), tax law (§ 147 AO, German Fiscal Code)
Employment contracts, payroll records 10 years § 147 AO, employment law obligations
T&C acceptance record (evidence of consent) 10 years Evidence of agreement; statutory limitation periods (§ 195 BGB)
ZAV work permit application documents 10 years Tax and social insurance law retention obligations
Contact data (for future job notifications) Until withdrawal of consent; max. 5 years after last programme participation Consent-based (Art. 6(1)(a) GDPR); annual review
Website log data (IP, technical data) 7 days Security and fraud prevention; legitimate interest
Contact form enquiries 3 years after closure of correspondence General limitation period for claims (§ 195 BGB)
Sensitive documents (passport, police clearance, uploads) and chat90 days after the status change that ends the programmeAutomatically removed from the platform; deleted immediately on account deletion
Core profile with talent-pool consent24 months, then we ask by email whether you want to stayConsent under Art. 6(1)(a); 30 days grace period, then deletion
Core profile without talent-pool consentDeleted completely once the period for sensitive data has passedNo further purpose
Push notification subscriptionUntil you withdraw, the account is deleted, or the address becomes invalidConsent under Art. 6(1)(a)
Email dispatch log30 daysProof of delivery, troubleshooting
Internal activity log12 monthsAccountability, Art. 5(2) GDPR
Internal meeting records12 monthsOrganisation of the programme
Documents kept by the employer (ABAX) outside this platform10 yearsStatutory retention duties of the employer (§ 147 AO, § 257 HGB)

Deleted user accounts (recovery window): When an account is deleted, the account data and uploaded documents are moved to an encrypted quarantine area for 14 days and are then erased irreversibly. This safeguard exists solely to allow recovery from accidental deletion. During this period the account is not active, cannot be used to log in and is not visible anywhere; access is restricted to administrators (Art. 6(1)(f) GDPR).

Account deletion

If your user account is deleted, all documents in your personal document area are immediately removed from the active system and moved to a locked quarantine area, where they are permanently erased after 24 hours. The quarantine exists solely to protect against accidental deletion. Records subject to statutory retention obligations (e.g. employment contracts and payroll records, see table above) are archived by the employer Abax Personaldienstleistungen GmbH outside the platform and retained for the statutory period of 10 years.
✓ Deletion on request Where no statutory retention obligation applies, we will delete your data on request prior to the expiry of the standard retention period. Please contact: datenschutz@ferienjobgermany.de
Services & Technologies Used
🔧
Section 7
Services, Tools & Data Processors

7.1 — Website Infrastructure (WordPress)

Our website is built on WordPress and hosted on a server located in Germany / the EU. WordPress itself is open-source software and does not transfer data to third parties. The hosting provider processes technical access data (IP address, timestamps, URLs accessed) under a Data Processing Agreement (DPA) pursuant to Art. 28 GDPR. To protect the website against attacks we use the security plugin Wordfence. If an attack is detected, the IP address concerned is transmitted to the provider Defiant Inc. (USA) so that known attackers can be blocked across sites. Data of ordinary visitors and applicants is not transmitted.

7.2 — Internal Data Management

Applicant data and programme documents are stored and processed within our own WordPress-based system, hosted on servers located in the European Union. We do not store applicant data in Google services. Please note: the chat assistant on our site loads its display fonts from Google Fonts (Google Ireland Ltd.) at runtime, which transmits your IP address to Google; see Section 7.14.

7.3 — Internal Automation

Administrative notifications and the synchronisation of applicant data are handled by internal processes within our own EU-hosted system. No data is transferred to external automation platforms.

7.4 — AI Assistant "Sophia"

Our digital assistant "Sophia" is provided using Botpress (see Section 7.6). In the context of the chat assistant, conversation content and any information entered by the user may be processed to provide the chatbot functionality. We strongly advise against entering particularly sensitive personal data into the chat assistant. Sophia is an artificial-intelligence (AI) system that generates its answers automatically; replies may therefore be incomplete or inaccurate and are not legally binding. Sophia does not take any decision about your application. All decisions regarding participation, placement or documents are taken by our staff, so no automated decision-making within the meaning of Art. 22 GDPR takes place. You can ask to be connected to a member of our team at any time.

7.5 — Email Communications

Email notifications to programme participants are sent via WordPress (wp_mail) through the SMTP service of our hosting provider in Germany (data processing agreement in place). The recipient's name and email address are processed for this purpose. Email content is not shared with third parties.

7.6 — Botpress (Chatbot Infrastructure)

For the interactive chat assistant (Sophia) on ferienjobgermany.de, we use Botpress (Botpress Inc., Montreal, Canada). Botpress processes conversation data to provide the chatbot functionality. A data processing agreement is currently being concluded; processing is based on EU Standard Contractual Clauses. Canada holds an EU adequacy decision for commercial data transfers. Botpress Privacy Policy: botpress.com/privacy

7.7 — Complianz (Cookie Consent Management)

We use Complianz (Complianz B.V., Groningen, Netherlands) to manage cookie consent. Complianz stores your cookie preferences locally in your browser and does not process personal data for its own purposes. Complianz Privacy Policy: complianz.io/privacy-statement/

7.8 — Backups

We create daily backups of the website and its database using the plugin UpdraftPlus in order to restore the service after technical failures (legitimate interest, Art. 6(1)(f) GDPR). The two most recent backup generations are kept on the hosting server in Germany; older backups are deleted automatically. Additional backup copies are stored offline on an encrypted local storage medium controlled by SHB Personalservice GmbH. Data deleted from the live system therefore disappears from the server backup cycle within a few days.

7.9 \u2014 Address geocoding (OpenStreetMap / Nominatim)

To calculate distances between accommodation and placement sites, address data is transmitted to the geocoding service Nominatim, operated by the OpenStreetMap Foundation (servers in the EU/UK). Only the address is transmitted, not your name. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in efficient accommodation planning).

7.10 \u2014 Script CDN (Cloudflare cdnjs)

To generate PDF documents in our internal administration area, a JavaScript library is loaded from the CDN cdnjs.cloudflare.com (Cloudflare Inc., USA). This affects only administrator devices, not applicants. The transfer is safeguarded by EU Standard Contractual Clauses.

7.11 \u2014 VAT validation (VIES)

When an employer registers, the VAT identification number is validated via the EU VIES service (European Commission, ec.europa.eu). This processes company data, not student personal data. Legal basis: Art. 6(1)(f) GDPR and legal obligation for correct invoicing.

7.12 — Push Notifications (Web Push)

If you switch on notifications in our web app, your browser creates a subscription and we store it in your account (a device-specific address plus two cryptographic keys). We use it to inform you about new messages, status changes and upcoming deadlines. Delivery is technically handled by the push service of your browser or device manufacturer — Google (Firebase Cloud Messaging), Apple or Mozilla — which involves a transfer to the USA (see Section 5). The content of each notification is encrypted; the push service cannot read it. Legal basis: Art. 6(1)(a) GDPR (consent). Notifications are never enabled automatically — you always have to press the button yourself. You can withdraw at any time in your browser or device settings; we delete the subscription on withdrawal, on account deletion, or when the address becomes permanently invalid.

7.13 — In-App Chat with our Team

Our portal and app include a chat you can use to reach our coordination team directly. We store the message content, sender, timestamp, read status and any files you attach (images or documents). Attachments are stored outside the publicly accessible area and are only delivered after an access check. Legal basis: Art. 6(1)(b) GDPR, as the chat is used to carry out the programme. Chat messages and attachments are deleted automatically 90 days after the last activity and immediately when your account is deleted; you may request earlier deletion at any time. The chat may also include group conversations created by our team (for example for a shared accommodation or workplace): messages you post in a group are visible to all group members together with your name, and group messages are deleted automatically after 90 days. Our team can additionally pin a message in a group and set internal reminders; these functions do not process any additional personal data.

7.14 — Google Fonts (via chat assistant)

The chat widget of our assistant loads web fonts from Google Fonts (Google Ireland Limited, Dublin). Your IP address is transmitted to Google for this purpose and may be processed on servers in the USA. Legal basis: Art. 6(1)(f) GDPR (uniform presentation); the widget only loads after you accept the corresponding cookie category. Google LLC is certified under the EU-US Data Privacy Framework.

7.15 — WhatsApp (Meta)

For quick coordination during the placement we also use WhatsApp (WhatsApp Ireland Limited, part of Meta). We process your phone number and the content of the messages you send us. Meta may transfer data to the USA on the basis of EU Standard Contractual Clauses; we have no influence on the processing carried out by Meta itself. Legal basis: Art. 6(1)(b) and Art. 6(1)(f) GDPR. WhatsApp is not mandatory: you can reach us equally through the chat in our app or by email, and we will use that channel if you prefer.

7.16 — Internal activity log

Administrative actions in our system (for example status changes, document approvals or deletions) are recorded with a timestamp, the acting staff member and the affected account. This serves to demonstrate compliance (Art. 5(2) GDPR) and to detect misuse; it also protects you, because it remains traceable who changed your data. No IP addresses are stored. Legal basis: Art. 6(1)(f) GDPR. Entries are deleted after 12 months.

7.17 — Police clearance certificate

The employer requires a police clearance certificate before you can start work. We collect it solely for this purpose, pass it on to the employer, and do not evaluate it ourselves. It is stored in the protected document area and is deleted from the platform together with the other sensitive documents (see Section 6). We do not process any information about pre-existing medical conditions: where the employer needs such information, you provide it to the employer directly and it is not stored in this platform.

7.18 — Is providing your data required, and where does it come from?

Providing the data marked as mandatory in the application is necessary for us to place you: without it we cannot apply for your work permit, prepare an employment contract or arrange accommodation, so we would not be able to accept your application. Everything else (for example the talent-pool consent or push notifications) is voluntary and has no effect on your application. Besides the data you give us yourself, we also receive information about you from the employer and, where applicable, from the German Federal Employment Agency (ZAV) — for instance a confirmation that a placement or a work permit has been granted or refused. We use that information solely to carry out the programme.
🍪
Section 8
Cookies & Tracking Technologies

Our website uses cookies and similar technologies. Cookies are small text files stored on your device. We use the following categories:

CategoryPurposeLegal BasisRetention
Strictly Necessary Session management, login state (WordPress), CSRF protection, cookie consent status No consent required (§ 25(2) TDDDG / ePrivacy) Session / up to 1 year
Functional Language preferences, user settings Art. 6(1)(a) GDPR (Consent) Up to 1 year
Analytics Statistical analysis of website usage (if enabled) Art. 6(1)(a) GDPR (Consent) Up to 2 years
You can adjust or withdraw your cookie preferences at any time via our Cookie Banner. Further information is available in our Cookie Policy. You may also disable cookies in your browser settings — please note that this may affect the functionality of the website.
📬
Section 9
Newsletter & Future Ferienjob Notifications

With your explicit consent, we retain your contact details (name, email address) after the conclusion of your programme participation in order to inform you about future Ferienjob programmes, new job opportunities, and other programme-related information.

Legal basis: Art. 6(1)(a) GDPR (Consent). Consent is obtained either in your profile at any time ("talent pool / retention" opt-in). This consent is voluntary and entirely separate from your application: without it, your core profile is deleted completely once the retention period for sensitive documents has passed. With it, we keep your core profile for 24 months so that we can tell you about suitable programmes; after 24 months we ask you by email whether you would like to stay, and if you do not reply within 30 days we delete your data. Without your explicit consent, we will not contact you for marketing purposes.
Right to withdraw: You may withdraw your consent at any time and without giving reasons — by clicking the unsubscribe link in any email, by emailing datenschutz@ferienjobgermany.de, or in your profile, where you can switch the talent-pool option off again at any time. Withdrawal does not affect the lawfulness of processing carried out prior to withdrawal.
Retention: Your contact data held for this purpose will be retained for a maximum of 5 years after your last programme participation, unless you withdraw consent earlier. An annual review is conducted.
🛡️
Section 10
Your Rights as a Data Subject (Art. 15–22 GDPR)

As a data subject, you have the following rights in relation to SHB Personalservice GmbH. To exercise your rights, please contact: datenschutz@ferienjobgermany.de

📋 Right of Access (Art. 15)
You have the right to obtain information about the personal data we process about you, including its origin, recipients, and purposes.
✏️ Right to Rectification (Art. 16)
You have the right to request the correction of inaccurate or incomplete data without undue delay.
🗑️ Right to Erasure (Art. 17)
You have the right to request the deletion of your data where no retention obligation applies ("right to be forgotten").
⏸️ Right to Restriction (Art. 18)
You may request that processing be restricted, for example while the accuracy of your data is under review.
📤 Right to Data Portability (Art. 20)
You have the right to receive your data in a structured, machine-readable format and to transfer it to another controller.
🚫 Right to Object (Art. 21)
You may object to the processing of your data on the basis of legitimate interests (Art. 6(1)(f)) at any time — in particular in relation to direct marketing.
⚠️ Right to Lodge a Complaint with a Supervisory Authority (Art. 77 GDPR) You have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your data infringes the GDPR.

Competent authority for Baden-Württemberg, Germany:
Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg (LfDI BW)
Lautenschlagerstraße 20, 70173 Stuttgart, Germany
📞 +49 711 / 615541-0 · 🌐 www.baden-wuerttemberg.datenschutz.de
We respond to requests to exercise data subject rights within 30 days of receipt. In the case of complex or multiple requests, this period may be extended by a further two months; we will notify you in advance in such cases.
🔐
Section 11
Data Security (Art. 32 GDPR)

We implement appropriate technical and organisational measures (TOMs) to protect your data in accordance with Art. 32 GDPR, including:

  • Encrypted data transmission via HTTPS/TLS (SSL certificate)
  • Access controls: only authorised staff and processors have access to personal data
  • Secure storage of uploaded documents in separate directories (fjg-docs, fjg-chat, fjg-meet) that are blocked against direct access by the web server and are only delivered after a permission check
  • Password hashing and hardened WordPress installation
  • Regular security updates and software patches
  • Role-based access control in the content management system
  • Nonce-based protection of all sensitive AJAX operations

In the event of a personal data breach posing a high risk to your rights and freedoms, we will notify you without undue delay pursuant to Art. 34 GDPR. Notifiable breaches will be reported to the competent supervisory authority within 72 hours (Art. 33 GDPR).

🔄
Section 12
Changes to this Privacy Policy

We reserve the right to update this Privacy Policy as necessary — in particular where legal requirements change or new services are introduced. The current version is always available at ferienjobgermany.de/datenschutz/.

In the event of material changes affecting your rights, registered users will be notified by email. The date of the most recent update is shown at the bottom of this page.

Version of this Policy: 26.08.2026 · Version 1.1
This Privacy Policy applies to ferienjobgermany.de and all associated sub-pages and services.