Privacy Policy
BID Bayerischer Inkasso Dienst GmbH
Stand: Juni 2026
The protection of your personal data and the safeguarding of your privacy are of paramount importance to the BID Group. We process personal data exclusively in compliance with the applicable data protection regulations, particularly the General Data Protection Regulation (GDPR) and the Federal Data Protection Act (BDSG).
This Privacy Policy applies to the use of the website provided at www.bid-coburg.de and the service portal, through which debt collection processes of BID Bayerischer Inkasso Dienst GmbH and other entities within the BID Group (specifically Profaktura Auslandsinkasso GmbH and ProCash Collection Services GmbH) are digitally managed.
Through these data protection notices, we inform you about the personal data we process when you use our website and service portal, the purposes for which this processing occurs, and the rights to which you, as the data subject, are entitled.
We implement technical and organizational measures to ensure a level of protection appropriate to the inherent risks and to safeguard your data against loss, misuse, unauthorized access, and unlawful disclosure.
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
BID Bayerischer Inkasso Dienst GmbH
Weichengereuth 26
96450 Coburg, Germany
Represented by the Managing Directors: Frank Fenske, Andreas Wöhner
Phone: 09561 8060-0
Fax: 09561 8060-805
Email: info@bid-coburg.de
Website: www.bid-coburg.de
Registry Court: Local Court Coburg, HRB 6053
VAT ID No.: DE 215572498
Registered debt collection service provider pursuant to Section 10 (1) No. 1 RDG. The supervisory/registration authority is the Federal Office of Justice, Department VII 5 (RDG), Adenauerallee 99-103, 53113 Bonn. Legal Services Register, File number: 2024 0001 0032.
BID Bayerischer Inkasso Dienst GmbH is the data protection controller responsible for the processing of personal data in connection with the operation of this website and the service portal.
2. Contact Details of the Data Protection Officer
Company Data Protection Officer:
Marco Groeger
Weichengereuth 26, 96450 Coburg
Email: datenschutz@bid-coburg.de
3. Accessing our Website (Server Log Files)
When you access our website, information is automatically collected by our web server and temporarily stored in so-called server log files. This includes, in particular:
- IP address of the requesting device
- Date and time of access
- Accessed page/file and transmitted data volume
- Notification of successful retrieval
The processing of this data serves to ensure a smooth connection setup, technical stability, and evaluation for IT security purposes (e.g., defense against attacks). The legal basis is Art. 6 (1) lit. f GDPR. Our legitimate interest lies in the operation and security of our website. No personal evaluation takes place; these data are not merged with other data sources.
Server log files are generally deleted after 90 days, unless further retention for evidentiary purposes is required in individual cases (e.g., during ongoing security investigations). In such cases, deletion occurs immediately after the reason for retention ceases to apply.
4. Use of Cookies and Access to End Devices
Diese Website setzt keine Cookies ein. Alle Funktionen arbeiten ohne Cookie-Speicherung.
5. Contacting Us
When you contact us (e.g., via email or our contact form), we process the personal data you provide (e.g., name, contact details, content of your inquiry) to process and respond to your request.
When using the contact form, the following information is collected as mandatory fields: name, email address, and message text. Further details are optional. The transmission of form data is encrypted via TLS/SSL.
The legal basis is Art. 6 para. 1 lit. b GDPR, provided your inquiry is related to the performance of a contract or pre-contractual measures, and otherwise Art. 6 para. 1 lit. f GDPR (legitimate interest in responding to inquiries). The data will be deleted as soon as the inquiry has been conclusively processed and no statutory retention obligations prevent deletion.
6. Use of the Service Portal
Through our service portal, you can manage collection cases asserted against you by the companies of the BID Group (BID Bayerischer Inkasso Dienst GmbH, Profaktura Auslandsinkasso GmbH, and ProCash Collection Services GmbH).
If you use our service portal, we process the data you enter (e.g., login data, case numbers, communication content, payment details) to provide online access to case data and to process your case (e.g., installment plan, notifications). It is at your discretion to what extent you use the service portal and enter your data; however, without the necessary information, use of the portal is not possible or only possible to a limited extent.
The legal basis is Art. 6 para. 1 lit. b GDPR (contract or pre-contractual measures), insofar as processing is necessary for the handling of the collection case, as well as Art. 6 para. 1 lit. f GDPR (legitimate interest in the efficient processing and documentation of receivables management). In the context of processing your collection case, personal data may be exchanged between BID Bayerischer Inkasso Dienst GmbH, Profaktura Auslandsinkasso GmbH, and ProCash Collection Services GmbH, to the extent necessary for the execution of receivables management or to fulfill legal obligations.
Log data (e.g., time of login, actions performed) is processed to ensure the security of the portal and to document processes comprehensibly. The storage duration is determined by the provisions of our deletion and blocking concept; specifically, the data is stored for the duration of the active processing of the case and subsequently blocked or deleted in accordance with statutory limitation and retention periods.
For processing payments within the service portal, we utilize the payment service provider Unzer Luxembourg S.A., Société anonyme, Parc d’Activité Syrdall 2, 18–20 rue Gabriel Lippmann, L-5365 Munsbach (hereinafter referred to as "Unzer").
During payment processing, the necessary personal data, specifically name, billing and, if applicable, shipping address, email address, payment data, and transaction data, are transmitted to Unzer.
Unzer processes this data as an independent controller within the scope of payment processing. For further information on data processing by Unzer, please refer to the provider's data protection notices at https://www.unzer.com/de/datenschutz/. Payment data is stored for a period of up to 10 years in accordance with commercial and tax law retention obligations (§ 257 HGB, § 147 AO).
Processing is carried out for the purpose of executing the payment and settling the underlying contractual relationship. The legal basis is Art. 6 para. 1 lit. b GDPR. Insofar as further legal obligations or legitimate interests exist, processing also occurs on this basis.
7. Purposes and Legal Bases of Processing
Unless otherwise stated in the preceding sections, we process personal data for the following purposes:
- Provision and Operation of the Website
- Responding to Inquiries
- Provision and utilization of the service portal
- Ensuring IT security
- Fulfillment of legal obligations (e.g., under HGB, AO)
The legal bases for this are, in particular:
- Art. 6 para. 1 lit. b GDPR (contract / pre-contractual measures)
- Art. 6 para. 1 lit. c GDPR (legal obligation)
- Art. 6 para. 1 lit. f GDPR (legitimate interests, e.g., efficient processing of transactions, IT security)
Insofar as we obtain consent in individual cases, the legal basis is Art. 6 para. 1 lit. a GDPR. Granted consent can be revoked at any time with future effect, e.g., by email to datenschutz@bid-coburg.de.
8. Recipients of Data / Processor Activities
Within the BID Group (comprising BID Bayerischer Inkasso Dienst GmbH, Profaktura Auslandsinkasso GmbH, and ProCash Collection Services GmbH), only those departments requiring access to your data for the stated purposes will receive it (specifically IT, accounts receivable management, service, and potentially Human Resources). The legal basis for intra-group data transfer is Art. 6 para. 1 lit. f GDPR (legitimate interest in efficient group-wide task distribution) or Art. 6 para. 1 lit. b GDPR, insofar as the transfer is necessary for contract fulfillment.
In the context of providing and maintaining our IT infrastructure, as well as hosting the website and service portal, we engage service providers who act as data processors for us in accordance with Art. 28 GDPR. These service providers have been carefully selected, are contractually obligated to comply with data protection requirements, and process personal data exclusively under our instruction. This specifically includes providers in the categories of web hosting and data center operations, IT infrastructure and system maintenance, and communication services. Processing is carried out exclusively on servers within the European Union or the European Economic Area.
Personal data is only transferred to other third parties if legally permitted or required (e.g., to authorities and courts when obligated) or if you have explicitly consented.
9. Third-Country Transfers
As a general rule, personal data is not transferred to recipients in countries outside the European Union (EU) or the European Economic Area (EEA) in connection with the website.
Should a third-country transfer be necessary in an individual case (e.g., when utilizing specific IT services), we ensure that an adequate level of data protection exists in accordance with Art. 44 et seq. GDPR, for instance, through EU Standard Contractual Clauses and supplementary measures.
10. Automated Decision-Making / Profiling
In the context of purely informational use of our website and the service portal, no automated decision-making, including profiling, within the meaning of Art. 22 GDPR takes place. Should this change in the future, we will inform you separately and, if necessary, obtain the required consents.
11. Data Retention Period
Unless a more specific storage duration is stated in this privacy policy, we store personal data only for as long as necessary to achieve the stated purposes or as required by statutory retention obligations.
Furthermore, we refer to our internal deletion and blocking concept, which provides differentiated periods for individual processing activities (e.g., accounts receivable management, portals, HR, applicants).
12. Right of Access Request under Art. 15 GDPR
You have the option to submit a request for information pursuant to Art. 15 GDPR via our website. For this purpose, we provide a form through which you can electronically transmit your access request to us. We process the data you enter exclusively for the purpose of handling and responding to your access request.
Within the form, the following data is processed in particular: first name, last name, email address, customer number or file reference, the content of your inquiry, and any other information you voluntarily provide. Mandatory fields are those details we require to assign and process your request. Processing is carried out on the basis of Art. 6 para. 1 lit. c GDPR to fulfill our legal obligation to provide you with the information requested under Art. 15 GDPR.
To prevent misuse and protect your data, we may request additional information for identity verification in cases of legitimate doubt. Your data will only be processed to the extent necessary for the review, processing, and response to the access request.
We process access requests without undue delay, and at the latest within one month of receipt. In justified cases, this period may be extended; we will inform you of this in due course. Upon completion of processing, the data will be deleted, unless statutory retention obligations or legitimate reasons for further storage exist.
Data Access
pursuant to Art. 15 GDPR
13. Your Rights as a Data Subject
In accordance with legal provisions, you have the following rights regarding your personal data:
- Right of Access (Art. 15 GDPR)
- Right to Rectification (Art. 16 GDPR)
- Right to Erasure (Art. 17 GDPR)
- Right to Restriction of Processing (Art. 18 GDPR)
- Right to Data Portability (Art. 20 GDPR)
- Right to Object to Specific Processing (Art. 21 GDPR)
Where we base processing on your consent, you have the right to withdraw this consent at any time with future effect (Art. 7 para. 3 GDPR).
Special Notice Regarding Your Right to Object Pursuant to Art. 21 GDPR
Insofar as we process your personal data based on our legitimate interests pursuant to Art. 6 para. 1 lit. f GDPR, you have the right, pursuant to Art. 21 GDPR, to object to this processing at any time on grounds relating to your particular situation. We will then no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights, and freedoms, or the processing serves the establishment, exercise, or defence of legal claims. To exercise your right to object, please contact us using the contact details provided above.
You also have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data infringes data protection regulations (Art. 77 GDPR). The supervisory authority responsible for our company is:
Bavarian State Office for Data Protection Supervision (BayLDA)
Promenade 18, 91522 Ansbach
Phone: 0981 180093-0
Email: poststelle@lda.bayern.de
Web: www.lda.bayern.de
To exercise your rights, you may contact the controller or the data protection officer using the contact details provided above.
14. Obligation to Provide Data
The provision of personal data is not required for purely informational use of our website. However, for the use of the service portal and the processing of specific inquiries (e.g., queries regarding a receivables process), the provision of certain data may be necessary; without this data, use of the portal or processing of your inquiry may not be possible or may be limited.
15. Data Security
We implement technical and organizational security measures to protect your data against accidental or intentional manipulation, loss, destruction, or unauthorized access by third parties. Our security measures are continuously improved in line with technological advancements.
For the secure transmission of data, we use TLS/SSL encryption. You can recognize an encrypted connection by the "https://" prefix and the padlock symbol in your browser's address bar.
16. Use of Plugins and Technical Extensions
Our website utilizes various technical extensions and plugins to provide and enhance its functionality, user-friendliness, accessibility, multilingualism, and security. Depending on the integrated function, this may involve the processing of personal data, particularly when content is loaded, settings are saved, or technical log data is processed. The legal basis, where necessary, is Art. 6 para. 1 lit. f GDPR, representing our legitimate interest in a secure, functional, and user-friendly web presence, and for functions requiring consent, Art. 6 para. 1 lit. a GDPR.
Specifically, we employ the following plugins and technical extensions:
- Yootheme Pro zur Gestaltung und technischen Bereitstellung der Website-Inhalte.
- Advanced Custom Fields zur strukturierten Verwaltung und Ausgabe von Website-Inhalten.
- Akeeba Backup for website backup and restoration. Technical data may be processed during backup and restoration procedures.
- Essentials für YOOtheme Pro (Anbieter: ZOOlanders) zur Erweiterung der Darstellungs- und Funktionalitätsmöglichkeiten der Website.
- Weglot zur Bereitstellung einer mehrsprachigen Website. Dabei können technisch erforderliche Informationen verarbeitet werden, um die gewählte Sprache anzuzeigen und die Funktion bereitzustellen.
- Vindicators Accessibility Plugin for enhancing the accessibility and user-friendliness of the website. To the extent that no personal data is processed thereby, its use has no separate data protection relevance.
- Wordfence Security zum Schutz der Website vor Angriffen, Schadsoftware und unbefugten Zugriffen (Firewall und Malware-Schutz). Zur Erkennung und Abwehr von Angriffen verarbeitet das Plugin technische Zugriffsdaten, insbesondere die IP-Adresse.
Insofar as individual plugins or extensions transmit personal data to third parties or access end devices, we provide separate information on this within the scope of the respective function.