BauFinBauFin
Company PanelPortalsUser GuideTradesDEMOPricingGPS TrackerTax Advisors
Company Panel – LoginSupport
🛡️
VOLLMACHT
BauFin|Power of Attorney

Power of Attorney for GDPR Request Handling

Power of attorney for handling data subject requests (GDPR Art. 15–22)

Courtesy translation — the German version (Vollmacht zur DSGVO-Bearbeitung) is legally binding.

Between the Controller’s company (hereinafter the “Controller”) and Krone Baustein e.K., trading as BauFin, represented by Krzysztof Jerzy Buczyński, owner, Eschenstieg 1, 20259 Hamburg (hereinafter “BauFin” or the “Processor”).

📄
01

§ 1 Subject and purpose

(1) This power of attorney supplements the data processing agreement (DPA) concluded between the parties under Art. 28 GDPR. (2) The Controller authorises BauFin — pursuant to Art. 28(3) sentence 2 point (e) GDPR in conjunction with a written arrangement — to operationally handle and answer, in the name and on the documented instructions of the Controller, data subject requests concerning: Art. 15 (access), Art. 16 (rectification), Art. 17 (erasure), Art. 18 (restriction), Art. 20 (portability), Art. 21 (objection), Art. 22 (right not to be subject to a decision based solely on automated processing). (3) Handling is performed in the name, on behalf and on the documented instructions of the Controller by trained staff. The authority covers research in the Controller’s data within the BauFin platform, preparing and sending the reply, and documentation in the audit log (Art. 5(2), Art. 12(3) GDPR). The record under Art. 30 GDPR remains unaffected.

🗂️
02

§ 2 Powers of the Processor

(1) BauFin may: a) receive requests, verify identity (Art. 12(6) GDPR) and assess plausibility; b) research, rectify, erase, restrict or export data within the Controller’s tenant — insofar as the request is justified; c) reply within the statutory period of one month (Art. 12(3) GDPR, extendable by two months); d) sign replies “on behalf and with power of attorney of the Controller, represented by BauFin / Krone Baustein e.K.”; e) document receipt, handling, decision and reply in the audit log. (2) NOT covered: a) decisions beyond mere request handling (e.g. terminating a contract with the data subject); b) responses to supervisory authority complaints (Art. 77 GDPR) — forwarded to the Controller without delay; c) information about data outside the BauFin platform (paper, other systems, local data); d) requests with identity doubts — forwarded to the Controller for clarification.

🔐
03

§ 3 Obligations of the Processor (BauFin)

(1) BauFin handles every request diligently and lawfully under Chapter III GDPR (Art. 12–23). (2) BauFin checks whether statutory retention duties (notably § 147 AO — 10 years for invoices, § 257 HGB — 6 years for business correspondence) prevent erasure; the data subject is informed (Art. 17(3)(b) GDPR). (3) BauFin informs the Controller without delay about: a) requests beyond the standard scope; b) personal data breaches (Art. 33 GDPR) — within 48 hours; c) requests it cannot technically or organisationally perform. (4) BauFin provides monthly reports on all handled requests (number, type, status, handling time). (5) Staff are trained and bound to confidentiality (Art. 28(3)(b) GDPR).

⚙️
04

§ 4 Obligations of the Controller

(1) The Controller remains legally responsible for data processing in its tenant under Art. 4(7) and Art. 5(2) GDPR. (2) The Controller keeps the data stored in the platform complete and up to date. (3) The Controller informs data subjects in its privacy policy that GDPR requests are handled by BauFin as a commissioned service provider. (4) Requests received directly (e.g. by post) may be entered into BauFin or handled by the Controller itself; the authority does not automatically extend outside the platform.

🌍
05

§ 5 Liability

(1) BauFin’s liability is governed by Art. 82 GDPR and the general provisions of the DPA. (2) BauFin is liable for intent and gross negligence; liability for slight negligence is limited to typical, foreseeable damage. (2a) Data subjects’ claims under Art. 82 GDPR and mandatory statutory liability towards third parties remain unaffected. (3) BauFin maintains professional IT liability insurance with sufficient cover. (4) Internally: mutual information on impending fines (Art. 83 GDPR) and coordinated defence towards supervisory authorities.

📎
06

§ 6 Revocation

(1) The Controller may revoke this authority at any time without reasons in text form, in particular by e-mail to [email protected]. (2) Revocation takes immediate effect for newly incoming requests; pending requests are — at the Controller’s choice — completed by BauFin or handed over with their current status. (3) After revocation, new requests are automatically forwarded to the Controller.

⚖️
07

§ 7 Term and final provisions

(1) The authority takes effect upon acceptance by the Controller (electronic click with date and IP logging) and applies until revoked or until the SaaS contract ends. (2) Amendments require text form (§ 126b BGB); updates are announced 30 days in advance and deemed accepted absent objection (opt-out). (3) Severability: invalidity of individual provisions does not affect the rest. (4) German law applies. Place of jurisdiction is Hamburg.

Accepted by: name of the authorised representative · date of electronic acceptance · IP address · audit log ID.

Information

  • About Us
  • FAQ
  • Comparison
  • Trades
  • For Tax Advisors
  • Save Time
  • Radio

The App

  • Guide
  • Pricing
  • DEMO
  • Tax Advisors
  • Portals
  • Company Panel
  • Customer Portal

Legal

  • Imprint
  • Privacy Policy
  • Terms
  • Right of Withdrawal
  • Cookie Policy
  • Data Processing Agreement
  • GDPR Power of Attorney

Help

  • Guide — Company Panel
  • Guide — Customer Portal
  • Guide — Accountant Portal
  • Guide — Subcontractor Portal
  • Guide — Employee Portal
  • Guide — GPS Tracker
  • Why not WhatsApp? NTFY!
© 2026 BauFin. All rights reserved.