Skip to main content Skip to main navigation Skip to footer

Privacy Notice for Suppliers, Service Providers, Business Partners, and Other External Entities

In this Privacy Notice, we provide information about how we process personal data in connection with the initiation, execution, and management of procurement, contractual, service, and collaborative relationships with suppliers, service providers, contractors, collaboration partners, other external entities, and contacts. For additional information regarding the handling of your personal data, please refer to the general privacy policy on our website:https://www.rwu.de/kontakt/datenschutz

Name and Address of the Data Controller

Controller within the meaning of Art. 4(7) of the GDPR:

Ravensburg-Weingarten University of Applied Sciences
Doggenriedstraße 70
D - 88250 Weingarten
Represented by: Rector Professor Dr.-Ing. Thomas Spägele

Tel: 0049 (0) 751/501-9344
Email: info@rwu.de
Website: https://www.rwu.de/

External Data Protection Officer

Our external data protection officer can be reached at:

Name: Benedict Lenz
Email: dsb@rwu.de
Website: https://www.exacon-gmbh.de

Information on Data Processing

Nature and Purpose of Processing

We process personal data in connection with the initiation, execution, and administration of procurement, contractual, service, and cooperation relationships with suppliers, service providers, contractors, cooperation partners, other external entities, and contacts.

In particular, this processing serves to review and process inquiries, conduct market research, prepare and carry out procurement and bidding procedures, solicit, review, and evaluate bids, applications for participation, and other procurement documents; the selection and engagement of suppliers and service providers; the preparation, execution, and fulfillment of contracts; communication with contacts; the coordination of deliveries, services, and other performance; the review of invoices and processing of payments; and the documentation of the respective relationship.

In addition, we process personal data to the extent necessary to fulfill legal obligations. These include, in particular, obligations under budgetary law, public procurement law, tax law, accounting law, and documentation and record-retention laws, as well as internal control, verification, and compliance requirements.

To the extent that access to our systems, premises, information, or other resources is required in the context of our collaboration, the processing may also serve the administration of access, authorization, and security processes. Processing takes place only to the extent necessary for the respective procurement, contractual, service, or cooperative relationship and the associated purposes.

Data Categories

In the context of establishing, execution, and administration of procurement, contractual, service, and cooperation relationships with suppliers, service providers, contractors, cooperation partners, other external entities, and contacts, we process—depending on the nature and scope of the respective relationship—in particular the following categories of personal data:

  • Master data: Last name, first name, organization, company, position, department, professional contact information, and other details for identifying and assigning the respective contact person.
  • Contact and communication data: Address, email address, phone number, content of communications, call and correspondence histories, and other information transmitted in the course of communication.
  • Procurement, Contract, and Service Data: Information regarding market research, bids, applications for participation, procurement documents, purchase orders, contracts, service descriptions, project details, deliveries, services, acceptance, complaints, warranty claims, and other information relevant to the execution of the respective procurement, contractual, service, or cooperative relationship.
  • Billing and payment data: Invoice data, bank account information, payment details, tax information, accounting entries, payment status, and other information required for invoice verification, payment processing, and bookkeeping.
  • Organizational and Documentation Data: Responsibilities, processing notes, transaction, procurement, and project data, supporting documents, minutes, approvals, audit notes, and other data required for the internal organization, documentation, tracking, and control of the respective relationship.
  • Access, Authorization, and Security Data: To the extent necessary, information regarding the management of access to premises, IT systems, platforms, or other resources, in particular user IDs, roles, permissions, access logs, visitor data, or security-related documentation.
  • Eligibility, Compliance, and Verification Data: Information required to meet legal, contractual, or internal requirements regarding documentation, control, eligibility, and compliance, in particular tax, commercial registry, business, insurance, qualification, certification, reference, or other eligibility documentation.

Legal Basis

The processing of personal data in connection with procurement, contractual, service, and cooperation relationships with suppliers, service providers, contractors, cooperation partners, other external entities, and contacts is based on the following legal grounds:

Art. 6(1)(e) GDPR in conjunction with § 4 LDSG BW: To the extent that processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority, the processing is based on Article 6(1)(e) of the GDPR in conjunction with Section 4 of the LDSG BW. This applies in particular to the organization, implementation, and documentation of the public entity’s procurement, award, contract, service, cooperation, invoicing, and communication processes. On this basis, personal data is processed in particular regarding contact persons, employees, representatives, or other points of contact of suppliers, service providers, contractors, cooperation partners, and other external entities, to the extent that this is necessary for the initiation, execution, administration, or settlement of the respective procurement, contractual, service, or cooperation relationship.

Art. 6(1)(b) GDPR: To the extent that the data subject is a party to the contract or the processing is necessary for the implementation of precontractual measures at the data subject’s request, the processing may additionally be based on Art. 6(1)(b) GDPR. This applies in particular to cases in which contracts or pre-contractual measures are carried out directly with natural persons, sole proprietors, independent service providers, or other natural persons as contracting parties.

Article 6(1)(c) of the GDPR: To the extent that personal data is processed to comply with legal obligations, the processing is based on Article 6(1)(c) of the GDPR. This applies in particular to obligations under budgetary law, public procurement law, tax law, accounting law, documentation and retention laws, as well as statutory obligations to provide evidence and cooperate.

Recipients and Transfers to Third Countries

Within our organization, access to personal data is granted to those departments that require it for the initiation, implementation, administration, or processing of the respective procurement, contractual, service, or cooperation relationship. This applies in particular to management, purchasing, the contracting authority, budget and financial administration, accounting, line departments, project managers, IT, administration, and other relevant internal departments.

Personal data may also be transferred to external recipients to the extent necessary for the initiation, execution, administration, or settlement of the respective procurement, contractual, service, or cooperation relationship; the processing of market inquiries, bids, applications for participation, award documents, purchase orders, contracts, deliveries, or services; the auditing of invoices; payment processing; the fulfillment of legal obligations; or the performance of public duties. These include, in particular, tax advisors, auditors, legal advisors, banks, payment service providers, insurance companies, shipping and logistics service providers, IT service providers, platform providers, government agencies, courts, auditing bodies, funding agencies, and other external entities, to the extent that such a transfer is necessary in the specific case or required by law.

To the extent that external service providers process personal data on our behalf, this is done on the basis of a data processing agreement in accordance with Article 28 of the GDPR.

Personal data is transferred to countries outside the European Union or the European Economic Area only if this is necessary in connection with the respective procurement, contractual, service, or cooperation relationship; the use of certain IT or communication services; or the involvement of external service providers. In such cases, a transfer to a third country takes place only under the conditions set forth in Articles 44 et seq. of the GDPR, in particular on the basis of an adequacy decision by the European Commission or appropriate safeguards such as EU Standard Contractual Clauses, as well as, where applicable, supplementary technical and organizational protection measures.

Retention Period

We process and store personal data in connection with procurement, contractual, service, and cooperation relationships with suppliers, service providers, contractors, cooperation partners, other external entities, and contacts only for as long as is necessary for the respective purposes.

Personal data of contacts, employees, representatives, or other contact persons is generally stored for the duration of the respective relationship or for as long as the respective person is relevant as a contact person for the respective procurement, contractual, service, or cooperation relationship.

If we are informed that a contact person is no longer responsible, has left the organization, company, or other external entity, or if their contact information is no longer current, the corresponding personal data will be deleted, blocked, or updated, provided that it is no longer necessary for the further processing of the respective relationship and there are no conflicting legal obligations regarding retention, documentation, or proof.

Personal data that forms part of procurement documents, contracts, purchase orders, bids, performance records, invoices, accounting records, business or administrative correspondence, or other documents subject to retention requirements may be stored for the duration of the applicable statutory retention periods. These may arise, in particular, from requirements under budgetary law, public procurement law, tax law, accounting law, or documentation and retention laws.

Data required to assert, exercise, or defend legal claims may also be stored for the duration of the applicable statutes of limitations. Upon expiration of the applicable retention or statute of limitations periods, the data will be deleted unless there is another legal basis for processing.

Consequences of Failure to Provide Data

The provision of personal data in connection with procurement, contractual, service, and cooperative relationships with suppliers, service providers, contractors, cooperation partners, other external entities, and contacts is generally required to the extent that the respective data is necessary for the initiation, execution, administration, or handling of the respective relationship.

If required personal data is not provided, this may result in market research, bids, applications for participation, or award documents may not be reviewed; contracts may not be prepared or executed; deliveries or services may not be coordinated; invoices may not be processed; or legal obligations regarding proof, documentation, and retention may not be fulfilled.

If personal data from contact persons, employees, representatives, or other points of contact is not provided or is not kept up to date, this may hinder or prevent communication and the proper handling of the respective procurement, contractual, service, or cooperative relationship.

Automated Decision-Making

No automated decision-making within the meaning of Article 22 of the GDPR takes place. Should we nevertheless implement such a procedure in individual cases in the future, we will inform you separately about this, provided that this is required by law.

Your Rights as a Data Subject

Data subjects may contact the controller or the data protection officer directly with any questions regarding data protection and the processing of their personal data.
 

Right of Access (Art. 15 GDPR)
You may request information about your stored data.

Right to Rectification (Art. 16 GDPR)
You may request that inaccurate data be corrected.

Right to erasure (Art. 17 GDPR)
You may request that we erase your data, provided the legal requirements are met.

Right to Restriction of Processing (Art. 18 GDPR)
You may request that the processing of your data be restricted, provided the legal requirements are met.

Right to Data Portability (Art. 20 GDPR)
To the extent that this is technically feasible, you have the right to receive your data in a structured, machine-readable format.

Right to Object (Art. 21 GDPR)
You may object to the processing of your data at any time for reasons arising from your particular situation, provided that the processing is based on Art. 6(1)(e) or (f) of the GDPR.

Right to Withdraw Consent (Art. 7(3) GDPR)
If you have given your consent todata processing, you may withdraw it at any time with future effect. Withdrawal does not affect the lawfulness of processing carried out on the basis of your consent prior to the withdrawal. Please direct your withdrawal to the contact information provided for the Data Protection Officer or the Data Controller.

Timeframes for Complying with Data Subjects’ Rights
We generally strive to respond to all requests within 30 days. However, this timeframe may be extended for reasons related to the specific right of the data subject or the complexity of your request.

Competent Supervisory Authority

We take your concerns and rights very seriously. However, if you believe that we have not adequately addressed your complaints or concerns, you have the right to file a complaint with a competent data protection authority:

The State Commissioner for Data Protection and Freedom of Information
P.O. Box 10 29 32
70025 Stuttgart
Phone: 07 11/61 55 41-0
Fax: 07 11/61 55 41-15