Privacy Policy
As at 9 September 2026
Preamble
With the following privacy policy we would like to inform you which types of your personal data (hereinafter also abbreviated as "data") we process for which purposes and in which scope. The privacy statement applies to all processing of personal data carried out by us, both in the context of providing our services and in particular on our websites, in mobile applications and within external online presences, such as our social media profiles (hereinafter collectively referred to as "online services").
The terms used are not gender-specific.
Last Update: 10. September 2026
Table of contents
- Preamble
- Controller
- Contact information of the Data Protection Officer
- Overview of processing operations
- Relevant legal bases
- Security measures
- Transmission of personal data
- International data transfers
- General information on data storage and deletion
- Rights of data subjects
- Business services
- Business processes and procedures
- Suppliers and services used in the course of business operations
- Provision of the online service and web hosting
- Use of Cookies
- Contact and enquiry management
- Artificial Intelligence (AI)
- Video conferencing, online meetings, webinars and screen sharing
- Cloud services
- Newsletters and electronic notifications
- Marketing communications via email, post, fax or telephone
- Surveys and polls
- Web analysis, monitoring and optimisation
- Online marketing
- Customer reviews and rating procedures
- social media presences
- Plug-ins and embedded functions as well as content
- Processing of data in the context of employment relationships
- Application process
- Privacy information for whistleblowers
- Whistleblower systems
- Modification and update
- Definitions of terms
Controller
LegalTegrity GmbH
Platz der Einheit 2
60327 Frankfurt
Authorised representatives: Dr Thomas Altenbach, Pia Michel
Email address contact@legaltegrity.com
Legal Notice: https://legaltegrity.com/en/legal-notice/
Contact information of the Data Protection Officer
Tina Walloscheck
Quasi Consult GbR
Gaußscher Bogen 11
29646 Bispingen
datenschutz@quasi-consult.de
Overview of processing operations
The following overview summarises the types of data processed and the purposes of their processing, and refers to the data subjects.
Types of processed data
- Master data.
- Employee data.
- Payment details.
- Contact details.
- Content data.
- Contract details.
- Usage data.
- Meta data, communication data and procedural data.
- Social data.
- Candidate data.
- Audio and/or video recordings.
- Audio recordings.
- Log data.
- Performance and behavioural data.
- Working hours data.
- Salary data.
Special categories of data
- Health data.
- Religious or philosophical beliefs.
- Trade union membership.
Categories of data subjects
- Beneficiary and client.
- Employees.
- Interested parties.
- Contact person.
- User.
- Applicant.
- Business and contractual partners.
- Participants.
- Persons shown.
- Third parties.
- Whistleblower.
- Customers.
Purposes of processing
- Provision of contractual services and fulfilment of contractual obligations.
- Communication.
- Security measures.
- Direct marketing.
- Audience measurement.
- Tracking.
- Office and organisational procedures.
- Remarketing.
- Conversion tracking.
- Click tracking.
- Target group identification.
- Organisational and administrative procedures.
- Application process.
- Feedback.
- Surveys and questionnaires.
- Marketing.
- Profiles with user-related information.
- Provision of our online offering and user-friendliness.
- Establishment and execution of employment relationships.
- IT infrastructure.
- Whistleblower protection.
- Financial and payment management.
- Public relations.
- Sales promotion.
- Business processes and operational procedures.
- Artificial Intelligence (AI).
Relevant legal bases
Relevant legal bases under the GDPR: Below you will find an overview of the legal bases of the GDPR on which we process personal data. Please note that, in addition to the provisions of the GDPR, national data protection regulations may apply in your or our country of residence or establishment. Furthermore, should more specific legal bases be relevant in individual cases, we will inform you of these in the privacy policy.
- Consent (Art. 6 (1) sentence 1 lit. a) GDPR) – The data subject has given consent to the processing of their personal data for one or more specific purposes.
- Performance of a contract and pre-contractual enquiries (Article 6(1)(b) GDPR) – The processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.
- Legal obligation (Article 6(1)(c) GDPR) – The processing is necessary for compliance with a legal obligation to which the controller is subject.
- Legitimate interests (Article 6(1)(f) GDPR) – processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data.
- Application procedure as a pre-contractual or contractual relationship (Art. 6 para. 1 sentence 1 lit. b) GDPR) – Insofar as special categories of personal data within the meaning of Art. 9(1) GDPR (e.g. health data, such as severe disability status or ethnic origin) are requested from applicants as part of the application procedure, so that the controller or the data subject can exercise the rights conferred on them by employment law and the law of social security and social protection and fulfil their obligations in this regard, their processing shall be carried out pursuant to Art. 9(2)(b) GDPR, in the event of the protection of the vital interests of the applicants or other persons pursuant to Art. 9(2)(c) GDPR, or for the purposes of preventive medicine or occupational medicine, for the assessment of the employee's capacity to work, for medical diagnosis, provision of health or social care or treatment, or the management of health or social care systems and services pursuant to Art. 9(2)(h) GDPR. In the event of a communication of special categories of data based on voluntary consent, their processing shall be carried out on the basis of Art. 9(2)(a) GDPR.
- Processing of special categories of personal data in relation to health, occupation and social security (Art. 9(2)(h) GDPR) – Processing is necessary for the purposes of preventive or occupational medicine, for the assessment of the working capacity of the employee, medical diagnosis, the provision of health or social care or treatment or the management of health or social care systems and services on the basis of Union or Member State law or pursuant to contract with a health professional.
National data protection regulations in Germany: In addition to the data protection regulations of the GDPR, national data protection regulations apply in Germany. These include, in particular, the Federal Data Protection Act (BDSG). The BDSG contains special provisions, in particular regarding the right of access, the right to erasure, the right to object, the processing of special categories of personal data, processing for other purposes, and transmission as well as automated individual decision-making, including profiling. Furthermore, state data protection acts of the individual federal states may apply.
Notice on the applicability of the GDPR and Swiss DPA: These data protection notices serve to provide information in accordance with both the Swiss Data Protection Act (DPA) and the General Data Protection Regulation (GDPR). For this reason, please note that the terms of the GDPR are used due to their broader territorial application and comprehensibility. In particular, instead of the terms „processing“ of „personal data“, „overriding interest“ and „particularly sensitive personal data“ used in the Swiss DPA, the terms „processing“ of „personal data“, „legitimate interest“ and „special categories of data“ used in the GDPR are applied. However, within the scope of application of the Swiss DPA, the legal meaning of the terms shall continue to be determined in accordance with the Swiss DPA.
Security measures
Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, we implement appropriate technical and organisational measures in accordance with statutory requirements to ensure a level of security appropriate to the risk.
The measures include, in particular, ensuring the confidentiality, integrity and availability of data by controlling physical and electronic access to the data as well as access to them, input, transfer, securing availability and their separation. Furthermore, we have established procedures to ensure the exercise of data subjects' rights, the erasure of data and responses to data security risks. In addition, we take the protection of personal data into account during the development or selection of hardware, software and procedures in accordance with the principle of data protection by design and by default.
Securing online connections using TLS/SSL encryption technology (HTTPS): To protect user data transmitted via our online services from unauthorised access, we rely on TLS/SSL encryption technology. Secure Sockets Layer (SSL) and Transport Layer Security (TLS) are the cornerstones of secure data transmission on the internet. These technologies encrypt the information transferred between the website or app and the user's browser (or between two servers), thereby protecting the data against unauthorised access. TLS, as the more advanced and secure version of SSL, ensures that all data transmissions meet the highest security standards. When a website is secured by an SSL/TLS certificate, this is indicated by the display of HTTPS in the URL. This serves as an indicator for users that their data is being transmitted securely and encrypted.
Transmission of personal data
As part of our processing of personal data, it may happen that this data is transmitted or disclosed to other bodies, companies, legally independent organisational units or persons. Recipients of this data may include, for example, service providers entrusted with IT tasks or providers of services and content that are integrated into a website. In such cases, we observe legal requirements and, in particular, conclude corresponding contracts or agreements with the recipients of your data that serve to protect your data.
International data transfers
Data processing in third countries: Insofar as we transfer data to a third country (i.e. outside the European Union (EU) or the European Economic Area (EEA)) or this occurs in the context of using third-party services or the disclosure or transfer of data to other persons, bodies or companies (which is recognisable from the postal address of the respective provider or if the privacy policy explicitly points out data transfer to third countries), this is always done in accordance with legal requirements.
For data transfers to the USA, we primarily rely on the Data Privacy Framework (DPF), which was recognised as a secure legal framework by an adequacy decision of the European Commission on 10 July 2023. In addition, we have concluded standard contractual clauses with the respective providers that comply with the requirements of the European Commission and establish contractual obligations for the protection of your data.
This dual safeguard ensures comprehensive protection of your data: the DPF forms the primary level of protection, while the standard contractual clauses serve as an additional safeguard. Should any changes occur within the framework of the DPF, the standard contractual clauses act as a reliable fallback option. This is how we ensure that your data remains adequately protected at all times, even in the event of any political or legal changes.
With the individual service providers, we inform you whether they are certified under the DPF and whether standard contractual clauses are in place. Further information on the DPF and a list of certified companies can be found on the US Department of Commerce website at https://www.dataprivacyframework.gov/ in English.
For data transfers to other third countries, appropriate security measures apply, in particular standard contractual clauses, explicit consents or legally required transfers. You can find information on third-country transfers and applicable adequacy decisions in the European Commission's information service: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection_en?prefLang=de.
General information on data storage and deletion
We delete personal data that we process, in accordance with statutory provisions, as soon as the underlying consents are revoked or there are no further legal bases for the processing. This concerns cases where the original purpose of the processing ceases to apply or the data is no longer required. Exceptions to this rule exist if legal obligations or special interests require a longer retention or archiving of the data.
In particular, data that must be retained for commercial or tax law reasons, or the storage of which is necessary for legal proceedings or for the protection of the rights of other natural or legal persons, must be archived accordingly.
Our privacy notice contains additional information on data retention and deletion that specifically applies to certain processing operations.
Where there are multiple specifications regarding the retention period or deletion deadlines for data, the longest period shall always apply. Data that is no longer retained for the originally intended purpose, but rather on the basis of legal requirements or other reasons, shall be processed by us exclusively for the reasons that justify its retention.
Storage and deletion of data: The following general time limits apply to retention and archiving under German law:
- 10 years – retention period for books and records, annual financial statements, inventories, management reports, opening balance sheets as well as the work instructions and other organisational documents required for understanding them (section 147(1) no. 1 in conjunction with subsec. 3 of the German Fiscal Code (AO), section 257(1) no. 1 in conjunction with subsec. 4 of the German Commercial Code (HGB)).
- 8 years – accounting records, such as invoices and expense receipts (Section 147(1) nos 4 and 4a in conjunction with (i.c.w.) para. 3 sentence 1 of the German Fiscal Code (AO), Section 14b(1) of the German VAT Act (UStG) and Section 257(1) no. 4 i.c.w. para. 4 of the German Commercial Code (HGB)).
- 6 years – Other business documents: received commercial or business letters, copies of dispatched commercial or business letters, other documents insofar as they are relevant for taxation purposes, e.g. hourly wage slips, cost centre accounting sheets, calculation documents, price tags, but also payroll accounting documents insofar as they are not already accounting vouchers, and till rolls (§ 147 para. 1 nos. 2, 3, 5 in conjunction with para. 3 AO [German Fiscal Code], § 257 para. 1 nos. 2 and 3 in conjunction with para. 4 HGB [German Commercial Code]).
- 3 years – data required to take into account potential warranty and damages claims or similar contractual claims and rights, and to process related enquiries based on previous business experience and standard industry practices, is stored for the duration of the regular statutory limitation period of three years (§§ 195, 199 BGB).
Start of period at the end of the year: If a period does not expressly begin on a specific date and is at least one year long, it automatically starts at the end of the calendar year in which the event triggering the period occurred. In the case of ongoing contractual relationships within the scope of which data is stored, the event triggering the period is the time at which the termination or other cessation of the legal relationship becomes effective.
Rights of data subjects
Data subject rights under the GDPR: As a data subject, you have various rights under the GDPR, which arise in particular from Articles 15 to 21 of the GDPR:
- Right to object: You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is based on Article 6(1)(e) or (f) GDPR; this also applies to profiling based on these provisions. Where personal data concerning you are processed for direct marketing purposes, you have the right to object at any time to the processing of personal data concerning you for such marketing; this also applies to profiling to the extent that it is related to such direct marketing.
- Right of withdrawal for consents: You have the right to withdraw any consents you have given at any time.
- Right to information You have the right to request confirmation as to whether data in question is being processed, to obtain information about this data, as well as further information and a copy of the data in accordance with the statutory provisions.
- Right of rectification In accordance with the statutory provisions, you have the right to request the completion of data concerning you or the rectification of incorrect data concerning you.
- Right to erasure and restriction of processing: You have the right, in accordance with statutory requirements, to demand that data concerning you be erased without undue delay, or alternatively to demand a restriction of the processing of the data in accordance with statutory requirements.
- Right to data portability: You have the right to receive data concerning you that you have provided to us in a structured, commonly used and machine-readable format, in accordance with statutory provisions, or to request its transmission to another controller.
- Complaint to supervisory authority: Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a data protection supervisory authority if you consider that the processing of your personal data infringes the GDPR. The complaint may be lodged, in particular, with a supervisory authority in the member state of your habitual residence, your place of work or the place of the alleged infringement.
Business services
We process personal data of our contractual and business partners, such as customers, clients, prospective clients, suppliers, and other cooperation partners (collectively referred to as „contractual partners“), for the initiation, execution, and handling of contractual relationships and comparable legal relationships. This also includes pre-contractual measures carried out upon request, as well as communication in connection with the respective contractual relationship.
The processing serves in particular the fulfilment of our primary and secondary contractual obligations. These include the provision of the agreed services, any update and information obligations, the handling of warranty claims and other performance disruptions, the processing of cancellations, terminations of ongoing contractual relationships, reversals, refunds, and the processing of other contract-related declarations and enquiries. This covers both one-off contracts and continuous contractual relationships.
In particular, master data such as name, address and, where applicable, company details, contact data such as email address and telephone number, contract and service data such as contract subject matter, contract term, order or transaction number, usage and service data, payment and billing data, as well as communication content and histories are processed. Where necessary, we also process data that is disclosed or transmitted to us in the course of executing an order.
In addition, we process the data to protect our rights and to comply with legal obligations. This includes, in particular, retention periods under commercial and tax law, documentation duties and, where applicable, obligations to provide evidence and accountability. Furthermore, processing is based on our legitimate interests in proper business management, internal administration, risk management and IT security, as well as in protecting our business operations and our contractual partners against misuse, threats to data, secrets and other legal assets. This may also include the involvement of external service providers such as IT and telecommunications providers, transport and logistics companies, payment service providers, banks, tax and legal advisors or other agents, insofar as this is necessary for the performance of the contract or to comply with legal obligations.
Personal data is only passed on to third parties to the extent that this is necessary for the performance of the contract, the implementation of pre-contractual measures, the protection of legitimate interests or the fulfilment of legal obligations. We provide separate information within this privacy policy regarding any processing that goes beyond this, in particular for marketing purposes.
Which data is required in each individual case will be communicated to the contractual partners during data collection, for example in online forms by appropriate labelling or during personal contact.
The data will be deleted as soon as it is no longer required for the aforementioned purposes and there are no statutory retention obligations to the contrary. Statutory retention periods, in particular under commercial and tax law, may require longer storage. Data transmitted in the context of a specific order will be deleted by us after completion of the order and expiry of any retention periods, provided there are no further statutory or contractual obligations to store the data.
The legal basis for the processing is Article 6(1)(b) of the GDPR for the implementation of pre-contractual measures and the performance of the respective contractual relationship, as well as Article 6(1)(c) of the GDPR for the fulfilment of legal obligations. In so far as the processing is based on legitimate interests, it is carried out on the basis of Article 6(1)(f) of the GDPR. In so far as the processing is based on Article 6(1)(f) of the GDPR, it is carried out to pursue our legitimate interests in the proper and efficient organisation of our business, internal administration and documentation of business transactions, the assertion and defence of legal claims, the ensuring of IT and data security, the prevention of abuse and fraud, as well as the economic management and further development of our business operations. These interests consist in particular in guaranteeing secure and legally compliant business operations and in safeguarding our entrepreneurial ability to act.
- Processed data types: Master data (e.g. full name, residential address, contact information, customer number, etc.); payment data (e.g. bank details, invoices, payment history); contact data (e.g. postal and email addresses or telephone numbers). Contract data (e.g. subject matter of the contract, term, customer category).
- Affected persons Beneficiaries and clients; prospective customers. Business and contractual partners.
- Purposes of processing and legitimate interests: Provision of contractual services and fulfilment of contractual obligations; communication; office and organisational procedures; organisational and administrative procedures. Business processes and operational procedures.
- Storage and deletion: Erasure in accordance with the details in the section „General Information on Data Storage and Erasure“.
- Legal basis: Performance of a contract and pre-contractual enquiries (Article 6(1)(b) GDPR); Legal obligation (Article 6(1)(c) GDPR); Legitimate interests (Article 6(1)(f) GDPR).
Further information on processing operations, procedures and services:
- Provision of software and platforms: We process the data of our customers and users (hereinafter uniformly referred to as „users“) in order to be able to provide our contractual services to them and, on the basis of legitimate interests, to ensure the security of our offering and to be able to develop it further; the required information is marked as such within the scope of the order, purchase or comparable conclusion of a contract and comprises the information required for the provision of services and billing as well as contact information in order to be able to hold any consultations; Legal basis: Performance of a contract and pre-contractual enquiries (Article 6(1)(b) GDPR), Legal obligation (Article 6(1)(c) GDPR), Legitimate interests (Article 6(1)(f) GDPR).
- IT services: We process the data of our customers and clients to enable them to plan, implement and support IT solutions and associated services. The required information is marked as such when concluding the order, project or comparable contract and includes the information required for service provision and billing, as well as contact information to enable any queries to be made. Insofar as we gain access to information belonging to end customers, employees or other persons, we process this in accordance with statutory and contractual requirements.
The processing operations include project management and documentation, which encompass all phases from the initial requirement analysis to the completion of the project. This involves creating and managing project schedules, budgets and resource allocations. Data processing also supports change management, where changes in the project workflow are documented and tracked to ensure compliance and transparency.
Another process is customer relationship management (CRM), which involves recording and analysing customer interactions and feedback in order to improve service quality and efficiently address individual customer needs. In addition, the processing procedure includes technical support and trouble-shooting, which encompasses the logging and processing of support requests, bug fixes and regular maintenance.
Furthermore, reporting and performance analysis are carried out, whereby key performance indicators are recorded and evaluated in order to assess the effectiveness of the provided IT solutions and continuously optimise them. All these processes are designed to ensure a high level of customer satisfaction and compliance with all relevant regulations; Legal basis: Performance of a contract and pre-contractual enquiries (Article 6(1)(b) GDPR), Legal obligation (Article 6(1)(c) GDPR), Legitimate interests (Article 6(1)(f) GDPR).
Business processes and procedures
Personal data of beneficiaries and clients – including customers, clients or, in special cases, principals, patients or business partners as well as other third parties – is processed within the context of contractual and comparable legal relationships and pre-contractual measures such as the initiation of business relationships. This data processing supports and facilitates business administration processes in areas such as customer management, sales, payment transactions, accounting and project management.
The collected data serve to fulfil contractual obligations and organise operational processes efficiently. This includes the processing of business transactions, the management of customer relationships, the optimisation of sales strategies and the assurance of internal accounting and financial processes. In addition, the data support the protection of the data controller's rights and promote administrative tasks and the organisation of the company.
Personal data may be disclosed to third parties if this is necessary for the fulfilment of the stated purposes or legal obligations. Upon expiry of statutory retention periods or if the purpose of the processing ceases to apply, the data will be erased. This also includes data that must be stored for a longer period due to tax law and statutory evidentiary obligations.
- Processed data types: Master data (e.g. full name, residential address, contact information, customer number, etc.); payment data (e.g. bank details, invoices, payment history); contact data (e.g. postal and email addresses or telephone numbers); content data (e.g. text or image messages and posts as well as information relating to them, such as details of authorship or time of creation); contract data (e.g. subject matter of the contract, term, customer category); log data (e.g. log files concerning logins or the retrieval of data or access times); usage data (e.g. page views and duration of stay, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions); meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, persons involved).
- Affected persons Recipients of services and clients; interested parties; communication partners; business and contractual partners; third parties; users (e.g. website visitors, users of online services); customers.
- Purposes of processing and legitimate interests: Provision of contractual services and fulfilment of contractual obligations; office and organisational procedures; business processes and management procedures; communication; marketing; sales promotion; public relations; financial and payment management. Information technology infrastructure (operation and provision of information systems and technical equipment (computers, servers, etc.)).
- Storage and deletion: Erasure in accordance with the details in the section „General Information on Data Storage and Erasure“.
- Legal basis: Performance of a contract and pre-contractual enquiries (Article 6(1)(b) GDPR); Legal obligation (Article 6(1)(c) GDPR); Legitimate interests (Article 6(1)(f) GDPR).
Further information on processing operations, procedures and services:
- Customer management and customer relationship management (CRM): procedures required within the context of customer management and customer relationship management (CRM) (e.g. customer acquisition in compliance with data protection regulations, measures to promote customer retention and loyalty, effective customer communication, complaint management and customer service with due regard for data protection, data management and analysis to support the customer relationship, management of CRM systems, secure account management, customer segmentation and target audience creation); Legal basis: Performance of a contract and pre-contractual enquiries (Art. 6(1)(b) GDPR), Legitimate interests (Art. 6(1)(f) GDPR).
- Contact management and relationship maintenance: procedures required for the organisation, maintenance and security of contact information (e.g. the setup and maintenance of a central contact database, regular updates of contact information, monitoring of data integrity, implementation of data protection measures, ensuring access controls, carrying out backups and restorations of contact data, training employees in the effective use of contact management software, regular review of communication history and adjustment of contact strategies); Legal basis: Performance of a contract and pre-contractual enquiries (Art. 6(1)(b) GDPR), Legitimate interests (Art. 6(1)(f) GDPR).
- General payment transactions: Procedures required for carrying out payment transactions, monitoring bank accounts and controlling payment flows (e.g. creation and checking of bank transfers, processing of direct debits, checking of bank statements, monitoring of incoming and outgoing payments, failed direct debit management, account reconciliation, cash management); Legal basis: Performance of a contract and pre-contractual enquiries (Art. 6(1)(b) GDPR), Legitimate interests (Art. 6(1)(f) GDPR).
- Bookkeeping, accounts payable, accounts receivable: Procedures required for the recording, processing and control of business transactions in accounts payable and accounts receivable accounting (e.g. creation and checking of incoming and outgoing invoices, monitoring and management of open items, execution of payment transactions, handling of the dunning process, account reconciliation in the context of receivables and payables, accounts payable accounting and accounts receivable accounting); Legal basis: Performance of a contract and pre-contractual enquiries (Article 6(1)(b) GDPR), Legal obligation (Article 6(1)(c) GDPR), Legitimate interests (Article 6(1)(f) GDPR).
- Financial accounting and taxes: Processes required for the recording, administration and control of financial transactions, as well as for the calculation, reporting and payment of taxes (e.g. coding and posting of business transactions, preparation of quarterly and annual financial statements, execution of payment transactions, handling of dunning procedures, account reconciliation, tax advice, preparation and submission of tax returns, management of taxation matters); Legal basis: Performance of a contract and pre-contractual enquiries (Article 6(1)(b) GDPR), Legal obligation (Article 6(1)(c) GDPR), Legitimate interests (Article 6(1)(f) GDPR).
- Sales: Processes required for the planning, implementation and monitoring of measures for the marketing and sale of products or services (e.g. customer acquisition, quotation preparation and follow-up, order processing, customer advice and support, sales promotion, product training, sales controlling and analysis, sales channel management); Legal basis: Performance of a contract and pre-contractual enquiries (Art. 6(1)(b) GDPR), Legitimate interests (Art. 6(1)(f) GDPR).
- Marketing, advertising and sales promotion: Processes required in the context of marketing, advertising and sales promotion (e.g. market analysis and target audience identification, development of marketing strategies, planning and implementation of advertising campaigns, design and production of advertising materials, online marketing including SEO and social media campaigns, event marketing and trade fair participation, customer loyalty programmes, sales promotion measures, performance measurement and optimisation of marketing activities, budget management and cost control); Legal basis: Legitimate interests (Article 6(1)(f) GDPR).
- Public relations procedures required within the scope of public relations and corporate communications (e.g., development and implementation of communication strategies, planning and execution of PR campaigns, creation and distribution of press releases, maintenance of media contacts, monitoring and analysis of media coverage, organisation of press conferences and public events, crisis communication, creation of content for social media and corporate websites, management of corporate branding); Legal basis: Legitimate interests (Article 6(1)(f) GDPR).
Suppliers and services used in the course of business operations
As part of our business operations and in compliance with legal requirements, we use additional third-party services, platforms, interfaces or plug-ins (referred to briefly as „services“). Their use is based on our interests in the proper, lawful and economical management of our business operations and our internal organisation.
- Processed data types: Master data (e.g. full name, residential address, contact information, customer number, etc.); payment data (e.g. bank details, invoices, payment history); contact data (e.g. postal and email addresses or telephone numbers); content data (e.g. text or image messages and posts as well as information relating to them, such as details of authorship or time of creation). Contract data (e.g. subject matter of the contract, term, customer category).
- Affected persons Beneficiaries and clients; prospective customers; business and contractual partners. Employees (e.g. staff, applicants, temporary workers and other personnel).
- Purposes of processing and legitimate interests: Provision of contractual services and fulfilment of contractual obligations; office and organisational procedures. Business processes and operational procedures.
- Storage and deletion: Erasure in accordance with the details in the section „General Information on Data Storage and Erasure“.
- Legal basis: Legitimate interests (Article 6(1)(f) GDPR). Performance of a contract and pre-contractual enquiries (Article 6(1)(b) GDPR).
Further information on processing operations, procedures and services:
- DATEV: Provision of cloud applications for accounting, payroll, document and data exchange, and collaboration with tax consultancies and companies. Processing, storage and transmission of data in data centres (servers) for the use of the respective applications; Service provider: DATEV eG, Paumgartnerstr. 6 – 14, 90429 Nuremberg, Germany; Legal basis: Legitimate interests (Article 6(1)(f) GDPR); Website https://www.datev.de/web/de/mydatev/datev-cloud-anwendungen/; Privacy policy: https://www.datev.de/web/de/berufsgruppenuebergreifend/ueber-datev/datenschutz-und-compliance/datenschutz-und-unternehmenssicherheit. Data Processing Agreement: Provided by the service provider.
- HubSpot CRM Management of customer contacts, tracking of sales activities, automation of marketing campaigns, analysis of sales data, creation and management of email campaigns, integration with other tools and platforms, management of customer support requests, AI-powered content generation, personalised email creation, predictive sales forecasts, automatic workflow descriptions and AI chatbots for customer interaction; Service provider: HubSpot Ireland Limited, Ground Floor, Two Dockland Central, Guild Street, Dublin 1, Ireland; Legal basis: Performance of a contract and pre-contractual enquiries (Art. 6(1)(b) GDPR), legitimate interests (Art. 6(1)(f) GDPR); Website https://www.hubspot.de/pa/crm; Privacy policy: https://legal.hubspot.com/de/privacy-policy; Data Processing Agreement: https://legal.hubspot.com/dpa. Legal basis for third country transfers: Data Privacy Framework (DPF), standard contractual clauses (https://legal.hubspot.com/dpa).
- Frisbii Management of subscriptions, recurring charges, invoices and payment processes; Service provider: Frisbii Germany GmbH, Mainzer Landstraße 51, 60329 Frankfurt am Main, Germany; Website https://frisbii.com/de/. Privacy policy: https://frisbii.com/de/datenschutzhinweise/.
Provision of the online service and web hosting
We process users' data in order to be able to provide them with our online services. For this purpose, we process the user's IP address, which is necessary to transmit the content and functions of our online services to the user's browser or end device.
- Processed data types: Usage data (e.g. page views and duration of visit, click paths, intensity and frequency of use, types of device used and operating systems, interactions with content and features); meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, persons involved). Log data (e.g. log files relating to logins or the retrieval of data or access times).
- Affected persons User (e.g. website visitors, users of online services).
- Purposes of processing and legitimate interests: Provision of our online services and user-friendliness; information technology infrastructure (operation and provision of information systems and technical equipment (computers, servers, etc.)); security measures.
- Storage and deletion: Erasure in accordance with the details in the section „General Information on Data Storage and Erasure“.
- Legal basis: Legitimate interests (Article 6(1)(f) GDPR).
Further information on processing operations, procedures and services:
- Provision of online service on rented storage space: To provide our online service, we use storage space, computing capacity and software which we rent or otherwise obtain from a corresponding server provider (also known as a „web host“); Legal basis: Legitimate interests (Article 6(1)(f) GDPR).
- Collection of access data and log files: Access to our online service is logged in the form of so-called „server log files“. The server log files may include the address and name of the retrieved web pages and files, date and time of retrieval, data volumes transferred, notification of successful retrieval, browser type and version, the user's operating system, referrer URL (the previously visited page) and, as a rule, IP addresses and the requesting provider. The server log files can be used, on the one hand, for security purposes, e.g. to prevent server overload (in particular in the event of abusive attacks, so-called DDoS attacks), and on the other hand, to ensure server utilisation and stability; Legal basis: Legitimate interests (Article 6(1)(f) GDPR). Deletion of data: Log file information is stored for a maximum of 30 days and is subsequently deleted or anonymised. Data whose further retention is required for evidentiary purposes is exempt from deletion until the respective incident has been finally resolved.
- Raidboxes: Services in the field of the provision of information technology infrastructure and related services (e.g. storage space and/or computing capacity); Service provider: RAIDBOXES GmbH, Hafenstraße 32, 48153 Münster, Germany; Legal basis: Legitimate interests (Article 6(1)(f) GDPR); Website https://raidboxes.io/; Privacy policy: https://raidboxes.io/legal/privacy/. Data Processing Agreement: https://helpcenter.raidboxes.de/de/articles/1947634-auftragsverarbeitungsvertrag-av.
Use of Cookies
The term „cookies“ refers to functions that store information on users' devices and read information from them. Cookies can also be used for various purposes, such as ensuring the functionality, security, and convenience of online services, as well as compiling analyses of visitor flows. We use cookies in accordance with legal regulations. To this end, where required, we obtain the users' consent in advance. If consent is not necessary, we rely on our legitimate interests. This applies when the storage and reading of information is essential in order to be able to provide explicitly requested content and functions. This includes, for example, saving settings and ensuring the functionality and security of our online service. Consent may be revoked at any time. We provide clear information about its scope and which cookies are used.
Notes on the legal bases under data protection law: Whether we process personal data using cookies depends on consent. If consent has been given, it serves as the legal basis. Without consent, we rely on our legitimate interests, which are explained above in this section and in the context of the respective services and procedures.
Retention period: With regard to the storage duration, a distinction is made between the following types of cookies:
- Temporary cookies (also: session cookies): Temporary cookies are deleted at the latest after a user leaves an online service and closes their device (e.g. browser or mobile application).
- Persistent Cookies Persistent cookies remain stored even after the device is closed. For example, this allows the login status to be saved and preferred content to be displayed directly when the user visits a website again. Likewise, user data collected using cookies can be used for audience measurement. Unless we provide users with explicit information on the type and storage duration of cookies (e.g. when obtaining consent), they should assume that these are persistent and that the storage duration can be up to two years.
General information on cancellation and objection (opt-out): Users can withdraw the consent they have given at any time and also object to the processing in accordance with legal requirements, including by using their browser's privacy settings.
- Processed data types: Meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, persons involved). Usage data (e.g. page views and dwell times, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions).
- Affected persons User (e.g. website visitors, users of online services).
- Purposes of processing and legitimate interests: Provision of our online offering and user-friendliness.
- Legal basis: Legitimate interests (Article 6(1)(f) GDPR). Consent (Article 6(1)(a) GDPR).
Further information on processing operations, procedures and services:
- Processing of cookie data on the basis of consent: We use a consent management solution with which users' consent to the use of cookies or to the procedures and providers named within the consent management solution is obtained. This procedure serves to obtain, log, manage and revoke consent, in particular with regard to the use of cookies and comparable technologies used to store, read out and process information on users' end devices. As part of this procedure, users' consent for the use of cookies and the associated processing of information, including the specific processing and providers named in the consent management procedure, is obtained. Users also have the option of managing and revoking their consent. The declarations of consent are stored in order to avoid having to prompt the user again and to be able to provide proof of consent in accordance with legal requirements. Storage takes place on the server side and/or in a cookie (so-called opt-in cookie) or by means of comparable technologies in order to be able to assign the consent to a specific user or their device. Unless specific information is available regarding the providers of consent management services, the following general information applies: The duration for which the consent is stored is up to two years. In the process, a pseudonymous user identifier is created, which is stored together with the time of the consent, details of the scope of the consent (e.g. relevant categories of cookies and/or service providers) and information about the browser, system and end device used; Legal basis: Consent (Art. 6(1)(a) GDPR).
- Cookie opt-out: In the footer of our website you will find a link that allows you to change your cookie settings and withdraw corresponding consents.
- Borlabs Cookie Storage and management of consents (consent to cookies and data processing), logging of user decisions, display of notices on data protection and cookies, enabling the withdrawal or adjustment of consents by users; Service provider: Execution on servers and/or computers under one's own data protection responsibility; Website https://de.borlabs.io/borlabs-cookie/. Further information: An individual user ID, language, as well as types of consent and the time of their submission are stored on the server side and in a cookie on the user's device.
- HubSpot Cookie Banner: Management of cookie consents and cookie preferences on our subdomain operated via HubSpot. Via the HubSpot cookie banner, website visitors can consent to or reject the use of optional cookies and similar technologies, and set their preferences by category. Technically necessary cookies are used to ensure the functionality of the consent management system and to store the selected preferences. The use of technically necessary technologies is based on Section 25(2)(2) of the TDDDG. Insofar as personal data is processed in this context, this is done on the basis of our legitimate interests in the legally compliant and user-friendly management of cookie preferences in accordance with Article 6(1), first sentence, point (f) of the GDPR. The use of optional cookies and tracking technologies takes place only with consent in accordance with Section 25(1) of the TDDDG and Article 6(1), first sentence, point (a) of the GDPR. Our HubSpot account is hosted in the EU data centre in Germany. Management of cookie consents and cookie preferences takes place on our subdomain operated via HubSpot. Via the HubSpot cookie banner, website visitors can consent to or refuse the use of optional cookies and similar technologies, as well as set their preferences by category. Technically necessary cookies are used to ensure the functionality of the consent management system and to store the selected preferences. The use of technically necessary technologies is based on Section 25(2)(2) of the TDDDG. Insofar as personal data is processed in this context, this is done on the basis of our legitimate interests in the legally compliant and user-friendly management of cookie preferences in accordance with Article 6(1), first sentence, point (f) of the GDPR. The use of optional cookies and tracking technologies takes place only with consent in accordance with Section 25(1) of the TDDDG and Article 6(1), first sentence, point (a) of the GDPR. Our HubSpot account is hosted in the EU data centre in Germany; Service provider: HubSpot Germany GmbH, Am Postbahnhof 17, 10243 Berlin, Germany; Website https://www.hubspot.de. Privacy policy: https://legal.hubspot.com/de/privacy-policy.
Contact and enquiry management
When contacting us (e.g. by post, contact form, email, telephone or via social media) and in the context of existing user and business relationships, the details provided by the enquiring persons are processed, insofar as this is necessary to respond to the contact enquiries and any requested measures.
- Processed data types: Contact details (e.g. postal and email addresses or telephone numbers). Content data (e.g. textual or visual messages and posts, as well as the information relating to them, such as details on authorship or time of creation).
- Affected persons Contact person.
- Purposes of processing and legitimate interests: Communication; organisational and administrative procedures; feedback (e.g. gathering feedback via online form). Provision of our online services and user-friendliness.
- Storage and deletion: Erasure in accordance with the details in the section „General Information on Data Storage and Erasure“.
- Legal basis: Legitimate interests (Article 6(1)(f) GDPR).
Further information on processing operations, procedures and services:
- HubSpot CRM Management of prospective clients, customers, and business contacts. HubSpot CRM is used for storing and processing contact data and enquiries, documenting communication and sales activities, managing sales opportunities and customer support enquiries, and for carrying out and evaluating marketing measures and automated processes. The legal bases are the performance of a contract and the implementation of pre-contractual measures pursuant to Art. 6 (1) sentence 1 lit. b GDPR, our legitimate interests in efficient customer, prospective client, and sales management pursuant to Art. 6 (1) sentence 1 lit. f GDPR and, where necessary, your consent pursuant to Art. 6 (1) sentence 1 lit. a GDPR. Our HubSpot account is hosted in the EU data centre in Germany; Service provider: HubSpot Germany GmbH, Am Postbahnhof 17, 10243 Berlin, Germany; Website https://www.hubspot.de. Privacy policy: https://legal.hubspot.com/de/privacy-policy.
- HubSpot Forms: Provision and management of online forms on our website and our subdomains operated via HubSpot. The forms are used in particular for contact and demo requests, event registrations and the provision of downloads. The information entered by the user is transmitted to our HubSpot CRM, where it is stored and processed to handle the respective request. The legal bases are the performance of pre-contractual measures pursuant to Art. 6(1)(1)(b) GDPR, our legitimate interests in the efficient processing of requests and the management of prospective customer contacts pursuant to Art. 6(1)(1)(f) GDPR and, insofar as consent is obtained, Art. 6(1)(1)(a) GDPR. Our HubSpot account is hosted in the EU data centre in Germany; Service provider: HubSpot Germany GmbH, Am Postbahnhof 17, 10243 Berlin, Germany; Website https://www.hubspot.de. Privacy policy: https://legal.hubspot.de/privacy-policy.
- Contact by phone: If you contact us by telephone or we contact you by telephone, we process the personal data arising in the course of the conversation. In particular, this may include your name, your telephone number, the time and duration of the call, the called or calling extension number, any content communicated by you and, where set up, voicemail messages. The processing is carried out for the purpose of handling your enquiry, initiating or performing a contractual relationship, and to safeguard our legitimate interests in efficient and traceable business communication. Depending on the reason, the legal basis is Art. 6 (1) sentence 1 lit. b GDPR and/or Art. 6 (1) sentence 1 lit. f GDPR. To provide our telephony infrastructure, we use Telekom Deutschland GmbH, Landgrabenweg 149, 53227 Bonn, Germany. To receive and handle calls, we use ebuero AG, Hauptstr. 8, 10827 Berlin, Germany. Insofar as the providers process personal data on our behalf, this is done on the basis of a data processing agreement pursuant to Art. 28 GDPR; Service provider: Telekom Deutschland GmbH, Landgrabenweg 149, 53227 Bonn, Germany; ebuero AG, Hauptstr. 8, 10827 Berlin, Germany; Website https://www.telekom.de/
https://www.ebuero.de/. Privacy policy: https://www.telekom.de/datenschutzhinweise https://www.ebuero.de/datenschutz.
Artificial Intelligence (AI)
We use Artificial Intelligence (AI), which involves the processing of personal data. The specific purposes and our interest in using AI are set out below. In accordance with the definition of an „AI system“ pursuant to Article 3(1) of the AI Regulation, we understand AI to be a machine-based system designed to operate with varying levels of autonomy, which may exhibit adaptability after deployment and which, for explicit or implicit objectives, infers from the input it receives how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments.
Our AI systems are deployed in strict compliance with legal requirements. These encompass both specific regulations for artificial intelligence and data protection provisions. In doing so, we adhere in particular to the principles of lawfulness, transparency, fairness, human oversight, purpose limitation, data minimisation, and integrity and confidentiality. We ensure that the processing of personal data is always based on a legal basis. This can be either the consent of the data subjects or a statutory permission.
When using external AI systems, we carefully select their providers (hereinafter referred to as „AI providers“). In accordance with our legal obligations, we ensure that the AI providers comply with applicable regulations. We also observe the obligations incumbent upon us when using or operating the AI services obtained. The processing of personal data by us and the AI providers is carried out exclusively on the basis of consent or legal authorization. In doing so, we place special emphasis on transparency, fairness and the maintenance of human control over AI-supported decision-making processes.
To protect the processed data, we implement appropriate and robust technical and organisational measures. These ensure the integrity and confidentiality of the processed data and minimise potential risks. By regularly reviewing the AI providers and their services, we ensure the ongoing compliance with current legal and ethical standards.
- Processed data types: Content data (e.g. text or image messages and posts as well as the information relating to them, such as details on authorship or time of creation); usage data (e.g. page views and duration of visit, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions); meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, persons involved); master data (e.g. full name, residential address, contact information, customer number, etc.). Contact data (e.g. postal and email addresses or telephone numbers).
- Affected persons Users (e.g. website visitors, users of online services); third parties; recipients of services and clients; communication partners. Customers.
- Purposes of processing and legitimate interests: Artificial intelligence (AI); office and organisational procedures; provision of our online service and user-friendliness; communication. Marketing.
- Storage and deletion: Erasure in accordance with the details in the section „General Information on Data Storage and Erasure“.
- Legal basis: Legitimate interests (Article 6(1)(f) GDPR). Consent (Article 6(1)(a) GDPR).
Further information on processing operations, procedures and services:
- Adobe AI: AI-driven tools and features in Adobe products that support creative processes. Adobe AI offers features such as automatic image editing, content generation and intelligent image adjustments to optimise the creative workflow; Service provider: Adobe Systems Software Ireland, 4-6 Riverwalk Drive, Citywest Business Campus, Brownsbarn, Dublin 24, D24 DCW0, Ireland; Legal basis: Legitimate interests (Article 6(1)(f) GDPR); Website https://business.adobe.com/de/ai/adobe-genai.html; Privacy policy: https://www.adobe.com/de/privacy.html; Data Processing Agreement: Provided by the service provider. Legal basis for third country transfers: Data Privacy Framework (DPF), Standard Contractual Clauses (Provided by the service provider).
- ChatGPT: AI-based service designed to understand and generate natural language and associated inputs and data, analyse information and make predictions („AI“, i.e. „artificial intelligence“, is to be understood in the sense of the term applicable in each case); Service provider: OpenAI Ireland Ltd, 117-126 Sheriff Street Upper, D01 YC43 Dublin 1, Ireland; Legal basis: Legitimate interests (Article 6(1)(f) GDPR); Website https://openai.com/de-DE/chatgpt/overview/; Privacy policy: https://openai.com/de-DE/policies/privacy-policy/. Right to object (opt-out): https://privacy.openai.com/policies?modal=select-subject.
- Microsoft Copilot: Microsoft Copilot: assistance with creating and editing texts, spreadsheets and presentations, data analysis, task automation and integration into Office applications. Content data (files, conversations, metadata) and employee credentials (Org ID / Entra ID) are processed for the purposes of increasing efficiency and productivity, cost efficiency, flexibility, mobility and integration with M365. Chat histories are stored for up to 30 days, and content until deleted by the user. In addition, diagnostic data is collected for product stability and improvement; Service provider: Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland; Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA; Legal basis: Legitimate interests (Article 6(1)(f) GDPR); Website https://www.microsoft.com/de-de/microsoft-copilot/organizations; Privacy policy: https://www.microsoft.com/de-de/privacy/privacystatement; Data Processing Agreement: https://www.microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA. Legal basis for third country transfers: Data Privacy Framework (DPF), standard contractual clauses (https://www.microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA).
- Perplexity: Perplexity AI enables the processing and provision of information using artificial intelligence. This includes answering questions, providing information based on web content, and supporting research through summarisation and referencing of relevant sources. In addition, the technology enables interaction in natural language to clarify ambiguities or to delve deeper into a topic. As part of its use, text input is automatically analysed and processed by artificial intelligence in order to generate contextual and precise answers. In the process, entered data may be processed to extract relevant information and optimise interaction with users. Furthermore, patterns in the transmitted data can be identified to continuously improve the quality of the answers. The provided functions can be used to personalise search queries and recommendations by taking previous interactions into account. User inputs are analysed in order to provide relevant results and ensure the most targeted communication of information possible. However, individual search queries are not saved, meaning that no permanent linking or tracking of queries takes place; Service provider: Perplexity AI, Inc., 575 Market St. Fl 4, 94105 San Francisco, USA; Legal basis: Legitimate interests (Article 6(1)(f) GDPR); Website https://www.perplexity.ai/; Privacy policy: https://www.perplexity.ai/de/hub/legal/privacy-policy. Legal basis for third country transfers: Data Privacy Framework (DPF).
- Canva: Creation and editing of graphics, presentations, videos and documents; real-time collaboration (simultaneous editing by multiple users); use of templates (pre-made layouts); uploading own media content; exporting and sharing created files; Service provider: Canva Pty Ltd, 110 Kippax St, 2010 Surry Hills, Australia; Legal basis: Consent (Art. 6 (1) sentence 1 lit. a) GDPR); Website http://www.canva.com/. Privacy policy: https://www.canva.com/de_de/richtlinien/privacy-policy/.
- HubSpot Breeze AI-powered service for task automation, customer data analysis, trend prediction, improving the personalisation of marketing strategies, and supporting decision-making processes; Service provider: HubSpot Ireland Limited, Ground Floor, Two Dockland Central, Guild Street, Dublin 1, Ireland; Legal basis: Legitimate interests (Article 6(1)(f) GDPR); Website https://www.hubspot.com/products/artificial-intelligence; Privacy policy: https://legal.hubspot.com/privacy-policy; Legal basis for third country transfers: Data Privacy Framework (DPF), standard contractual clauses (yes). Further information: https://legal.hubspot.com/dpa.
- Sales Automation.ai AI-powered lead generation via LinkedIn. The platform is used for the research, identification, enrichment and qualification of potentially relevant business contacts on LinkedIn. In particular, names, professional roles, company affiliations, publicly accessible profile data and other business contact data may be processed. The legal basis is our legitimate interest in identifying suitable business contacts and targeted B2B sales outreach in accordance with Art. 6(1) sentence 1 lit. f GDPR. According to the provider, the data is hosted in German data centres; Service provider: Sales Automation GmbH, Kürnbergstr. 28, 81369 Munich, Germany; Website https://sales-automation.ai. Privacy policy: https://sales-automation.notion.site/Datenschutzbestimmungen-453bd4554fb04a03b5c8b2f616a60648.
Video conferencing, online meetings, webinars and screen sharing
We use platforms and applications of other providers (hereinafter referred to as „conference platforms“) for the purpose of conducting video and audio conferences, webinars, and other types of video and audio meetings (hereinafter collectively referred to as „conferences“). When selecting the conference platforms and their services, we observe the statutory requirements.
Data processed by conference platforms: As part of participation in a conference, the conference platforms process the personal data of participants listed below. The scope of processing depends, on the one hand, on which data are required for a specific conference (e.g. provision of login details or real names) and which optional information is provided by the participants. In addition to processing for the purpose of holding the conference, participants' data may also be processed by the conference platforms for security purposes or service optimisation. The data processed include personal data (first name, surname), contact information (email address, telephone number), login details (access codes or passwords), profile pictures, information on professional status/position, the IP address of the internet connection, information on the participants' end devices, their operating system, the browser and its technical and linguistic settings, information on communication processes, i.e. entries in chats as well as audio and video data, and the use of other available functions (e.g. surveys). The content of communications is encrypted to the extent technically provided by the conference providers. If participants are registered as users with the conference platforms, further data may be processed in accordance with the agreement with the respective conference provider.
Logging and recordings: Where text inputs, participation results (e.g. from surveys) as well as video or audio recordings are logged, participants will be informed of this transparently in advance and, where necessary, asked for their consent.
Data protection measures of the participants: Please refer to the data protection notices of the conference platforms for details regarding the processing of your data, and select the security and privacy settings that are best for you within the conference platform settings. Furthermore, for the duration of a video conference, please ensure data protection and personal privacy in the background of your recording (e.g. by informing flatmates, locking doors and using the background blur function, where technically possible). Links to the conference rooms and access data must not be passed on to unauthorised third parties.
Notes on Legal Basis: If, in addition to the conference platforms, we also process users' data and ask users for their consent to the use of the conference platforms or certain functions (e.g. consent to the recording of conferences), the legal basis for the processing is this consent. Furthermore, our processing may be necessary for the performance of our contractual obligations (e.g. for attendee lists, in the case of processing meeting outcomes, etc.). Otherwise, users' data will be processed on the basis of our legitimate interests in efficient and secure communication with our communication partners.
- Processed data types: Master data (e.g. full name, residential address, contact information, customer number, etc.); contact data (e.g. postal and email addresses or telephone numbers); content data (e.g. textual or visual messages and posts as well as information relating to them, such as details on authorship or time of creation); usage data (e.g. page views and dwell time, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and features); image and/or video recordings (e.g. photographs or video recordings of a person); audio recordings; log data (e.g. log files relating to logins or the retrieval of data or access times); contract data (e.g. subject matter of the contract, term, customer category). Meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, persons involved).
- Affected persons Communication partners; users (e.g. website visitors, users of online services); depicted persons; recipients of services and clients; prospective customers; participants.
- Purposes of processing and legitimate interests: Provision of contractual services and fulfilment of contractual obligations; communication; office and organisational procedures. Provision of our online service and user-friendliness.
- Storage and deletion: Erasure in accordance with the details in the section „General Information on Data Storage and Erasure“.
- Legal basis: Legitimate interests (Article 6(1)(f) GDPR).
Further information on processing operations, procedures and services:
- Microsoft Teams Use for holding online events and conferences, as well as communication with internal and external participants. Voice transmission, direct messages, group communication and collaboration features are used; processed are name, business contact details, work profile, participation and content (audio/video, voice, chat, files, voice transcription) for the purposes of and based on the interest in increasing efficiency and productivity, cost-efficiency, flexibility, mobility, improved communication, IT security, use of a centralised platform and conducting Microsoft's business operations. Audio signals are generally not stored, unless recording is activated. Meeting and conference recordings are stored for 90 days by default, unless a different duration is specified. Chat and file contents are stored in accordance with the policies determined by the administrator or user; the default setting is no automatic deletion. Channels must be renewed every 180 days, otherwise contents are deleted. In addition, system-generated log, diagnostic and metadata are processed, and diagnostic data is collected for product stability, security and improvement; Service provider: Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland; Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA; Legal basis: Legitimate interests (Article 6(1)(f) GDPR); Website https://www.microsoft.com/de-de/microsoft-teams/; Privacy policy: https://www.microsoft.com/de-de/privacy/privacystatement. Legal basis for third country transfers: Data Privacy Framework (DPF), standard contractual clauses (https://www.microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA).
Cloud services
We use software services accessible via the internet and executed on their providers„ servers (known as “cloud services„, also referred to as “Software as a Service") for the storage and management of content (e.g. document storage and management, exchange of documents, content and information with specific recipients, or publication of content and information).
Within this framework, personal data may be processed and stored on the providers' servers, provided that this data forms part of communications with us or is otherwise processed by us as set out in this privacy policy. Such data may include, in particular, master data and contact data of users, data relating to transactions, contracts, other processes and their contents. The cloud service providers also process usage data and metadata, which they use for security purposes and service optimisation.
Where we make forms or other documents and content available to other users or publicly accessible websites with the help of cloud services, the providers may store cookies on the users' devices for web analytics purposes or to remember user settings (e.g. in the case of media control).
- Processed data types: Master data (e.g. full name, residential address, contact information, customer number, etc.); contact details (e.g. postal and email addresses or telephone numbers); content data (e.g. textual or visual messages and posts as well as information relating to them, such as details on authorship or time of creation); usage data (e.g. page views and dwell time, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and functions). Image and/or video recordings (e.g. photographs or video recordings of a person).
- Affected persons Prospective clients; communication partners. Business and contractual partners.
- Purposes of processing and legitimate interests: Office and organisational procedures; Information technology infrastructure (operation and provision of information systems and technical equipment (computers, servers, etc.)). Provision of contractual services and fulfilment of contractual obligations.
- Storage and deletion: Erasure in accordance with the details in the section „General Information on Data Storage and Erasure“.
- Legal basis: Legitimate interests (Article 6(1)(f) GDPR).
Further information on processing operations, procedures and services:
- Adobe Creative Cloud: Cloud storage, cloud infrastructure services and cloud-based application software, including for photo editing, video editing, graphic design, web development; Service provider: Adobe Systems Software Ireland, 4-6 Riverwalk Drive, Citywest Business Campus, Brownsbarn, Dublin 24, D24 DCW0, Ireland; Legal basis: Legitimate interests (Article 6(1)(f) GDPR); Website https://www.adobe.com/de/creativecloud.html; Privacy policy: https://www.adobe.com/de/privacy.html; Data Processing Agreement: Provided by the service provider. Legal basis for third country transfers: Data Privacy Framework (DPF), Standard Contractual Clauses (Provided by the service provider).
- Microsoft 365 and Microsoft cloud services: Provision of applications, protection of data and IT systems, and use of system-generated log, diagnostic and metadata for the performance of the contract by Microsoft. Contact data (name, email address), content data (files, comments, profiles), software setup and inventory data, device connectivity and configuration data, work interactions (badge swipe) as well as log and metadata are processed. Processing is carried out for the purposes of efficiency and productivity enhancements, cost efficiency, flexibility, mobility, improved communication, integration of Microsoft services, IT security and Microsoft's business operations. Data retention is based on the respective documents and corporate policies, up to 12 months for Defender (protection of data and IT systems), and 10 days for print management. In addition, diagnostic data is collected for product stability and improvement; Service provider: Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland; Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA; Legal basis: Legitimate interests (Article 6(1)(f) GDPR); Website https://www.microsoft.com/de-de; Privacy policy: https://privacy.microsoft.com/de-de/privacystatement, Safety instructions: https://www.microsoft.com/de-de/trustcenter; Data Processing Agreement: https://www.microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA. Legal basis for third country transfers: Data Privacy Framework (DPF), standard contractual clauses (https://www.microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA).
- Microsoft EU Data Boundary: Our use of Microsoft cloud services takes place within the framework of the so-called „EU Data Boundary“ (also referred to as the „EU-Datengrenze“), which ensures that data is stored and processed within the European Union (EU) and the European Free Trade Association (EFTA).
The EU Data Boundary is a defined region in which Microsoft undertakes to store and process customer data and personal data for specific online services (Microsoft 365, Azure, Dynamics 365 and the Power Platform). Companies that use these services can ensure that their data remains within the EU/EFTA region. This includes both general customer data and support data generated as part of technical services. In many cases, pseudonymised data is also processed within this region.
The EU Data Boundary encompasses all EU countries as well as the EFTA states (Liechtenstein, Iceland, Norway and Switzerland). Microsoft operates datacentres in several of these countries, including Germany, France, Ireland, the Netherlands, Sweden, Spain and Switzerland. Further locations may be added.
As part of its operations, Microsoft automatically creates logs to ensure the security and functionality of its services. These logs primarily contain technical information, but in certain cases may also include personal data, such as when user actions are documented.
To protect this data, Microsoft uses techniques such as encryption, masking and tokenisation (replacing sensitive data with untraceable character strings). This ensures that Microsoft employees only see pseudonymised data and cannot draw direct conclusions about individual users. There are also strict access rules and retention periods for this data.
Microsoft has assured that data transfers outside the EU will only take place in a few precisely defined cases. This may be necessary, for example, to implement global cybersecurity measures or to ensure the functionality of cloud services. These transfers always take place under high security standards such as encryption and pseudonymisation.
Further information on the EU Data Boundary and Microsoft's data protection measures can be found in the Microsoft EU Data Boundary Trust Center: https://www.microsoft.com/de-de/trust-center/privacy/european-data-boundary-eudb. - Nextcloud: Cloud storage, cloud infrastructure services and cloud-based application software; Service provider: Nextcloud GmbH, Hauptmannsreute 44a, 70192 Stuttgart, Germany; Legal basis: Legitimate interests (Article 6(1)(f) GDPR); Website https://nextcloud.com/de/. Privacy policy: https://nextcloud.com/de/privacy/.
Newsletters and electronic notifications
We send newsletters, emails and other electronic notifications (hereinafter referred to as „newsletters“) exclusively with the consent of the recipients or on the basis of a legal provision. If the contents of the newsletter are specified during the registration process, these contents shall be decisive for the user's consent. To register for our newsletter, providing your email address is normally sufficient. However, in order to be able to offer you a personalised service, we may ask you to provide your name for a personal address in the newsletter or further information, should this be necessary for the purpose of the newsletter.
Erasure and restriction of processing: We may store unsubscribed email addresses for up to three years on the basis of our legitimate interests before deleting them, in order to be able to prove consent that was formerly given. The processing of this data is restricted to the purpose of potentially defending against claims. An individual request for erasure is possible at any time, provided that the former existence of consent is confirmed at the same time. In the case of obligations to permanently observe objections, we reserve the right to store the email address solely for this purpose on a blocklist.
The logging of the registration procedure is carried out on the basis of our legitimate interests for the purpose of proving that it was conducted properly. Insofar as we commission a service provider to send emails, this is done on the basis of our legitimate interests in an efficient and secure dispatch system.
ContentsInformation about us, our services, product updates, promotions, events and offers.
- Processed data types: Master data (e.g. full name, residential address, contact information, customer number, etc.); contact details (e.g. postal and email addresses or telephone numbers); meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, persons involved). Usage data (e.g. page views and duration of visit, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions).
- Affected persons Contact person.
- Purposes of processing and legitimate interests: Direct marketing (e.g. by email or post).
- Legal basis: Consent (Article 6(1)(a) GDPR). Legitimate interests (Article 6(1)(f) GDPR).
- Right to object (opt-out): You can cancel your subscription to our newsletter at any time, i.e. revoke your consent or object to receiving it in future. You can find a link to unsubscribe from the newsletter either at the end of each newsletter or otherwise use one of the contact options given above, preferably email, for this purpose.
Further information on processing operations, procedures and services:
- Measurement of open and click-through rates: The newsletters contain a so-called „web beacon“, i.e. a pixel-sized file which is retrieved from our server or that of our mailing service provider, if we use one, when the newsletter is opened. As part of this retrieval, technical information such as details about the browser and your system, as well as your IP address and the time of retrieval, are initially collected. This information is used for the technical improvement of our newsletter based on the technical data or the target groups and their reading behaviour based on their retrieval locations (which can be determined using the IP address) or access times. This analysis also includes determining whether and when the newsletters are opened and which links are clicked. The collected information is assigned to individual newsletter recipients and stored in their profiles until deletion. User profiles are created on this basis, in which usage behaviour and user characteristics are stored. The measurement of open and click rates as well as the storage of the measurement results in the users' profiles and their further processing are based on user consent. Unfortunately, a separate revocation of the performance measurement is not possible; in this case, the entire newsletter subscription must be cancelled or objected to. In this case, the stored profile information will be deleted; Legal basis: Consent (Art. 6(1)(a) GDPR).
- HubSpot Email Marketing: Dispatch of emails, creation of personalised campaigns, automation of workflows, segmentation of target audiences, integration with CRM systems, analysis of performance through reports and dashboards; Service provider: HubSpot Ireland Limited, Ground Floor, Two Dockland Central, Guild Street, Dublin 1, Ireland; Legal basis: Legitimate interests (Article 6(1)(f) GDPR); Website https://www.hubspot.com/products/marketing/email; Privacy policy: https://legal.hubspot.com/de/privacy-policy; Data Processing Agreement: https://legal.hubspot.com/dpa. Legal basis for third country transfers: Data Privacy Framework (DPF), standard contractual clauses (https://legal.hubspot.com/dpa).
Marketing communications via email, post, fax or telephone
We process personal data for the purposes of promotional communication, which may take place via various channels, such as email, telephone, post or fax, in accordance with legal requirements.
Recipients have the right to withdraw given consent at any time or to object to promotional communication free of charge using the contact option specified above.
Following revocation or objection, we store the contact details or data required to prove the previous authorisation for up to three years after the end of the year in which the revocation or objection took place, based on our legitimate interests. The processing of this data is restricted to the purpose of potentially defending against claims. Based on the legitimate interest in permanently respecting users' revocation or objection, we also store the data required to avoid future contact (e.g., depending on the communication channel, the email address, phone number, name).
- Processed data types: Master data (e.g. full name, residential address, contact information, customer number, etc.); contact data (e.g. postal and email addresses or telephone numbers). Content data (e.g. text or image messages and posts as well as information relating to them, such as details on authorship or time of creation).
- Affected persons Contact person.
- Purposes of processing and legitimate interests: Direct marketing (e.g. by email or post); marketing; sales promotion.
- Storage and deletion: Erasure in accordance with the details in the section „General Information on Data Storage and Erasure“.
- Legal basis: Consent (Article 6(1)(a) GDPR). Legitimate interests (Article 6(1)(f) GDPR).
Surveys and polls
We conduct surveys and questionnaires to collect information for the respectively communicated purpose of the survey or questionnaire. The surveys and questionnaires conducted by us (hereinafter referred to as „surveys“) are evaluated anonymously. Personal data is only processed to the extent necessary for the provision and technical implementation of the surveys (e.g. processing the IP address in order to display the survey in the user's browser or using a cookie to enable the survey to be resumed).
- Processed data types: Master data (e.g. full name, residential address, contact information, customer number, etc.); contact details (e.g. postal and email addresses or telephone numbers); content data (e.g. text or image messages and posts as well as information relating to them, such as details on authorship or time of creation); usage data (e.g. page views and dwell time, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and functions); contract data (e.g. subject matter of the contract, term, customer category). Meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, persons involved).
- Affected persons Participants; beneficiaries and clients; prospective clients; communication partners. Business and contractual partners.
- Purposes of processing and legitimate interests: Feedback (e.g. collecting feedback via online form); surveys and questionnaires (e.g. surveys with input options, multiple-choice questions); provision of contractual services and fulfilment of contractual obligations; communication. Office and organisational procedures.
- Storage and deletion: Erasure in accordance with the details in the section „General Information on Data Storage and Erasure“.
- Legal basis: Legitimate interests (Article 6(1)(f) GDPR).
Further information on processing operations, procedures and services:
- HubSpot Service Hub Management of customer inquiries, tracking of support tickets, provision of a knowledge base, collection of customer feedback, automation of customer communication, creation of reports and analytics, monitoring of service level agreements; Service provider: HubSpot Ireland Limited, Ground Floor, Two Dockland Central, Guild Street, Dublin 1, Ireland; Legal basis: Legitimate interests (Article 6(1)(f) GDPR); Website https://www.hubspot.com/products/service; Privacy policy: https://legal.hubspot.com/privacy-policy; Legal basis for third country transfers: Data Privacy Framework (DPF), standard contractual clauses (yes). Further information: https://legal.hubspot.com/dpa.
Web analysis, monitoring and optimisation
Web analytics (also referred to as audience measurement) is used to evaluate visitor flows to our online service and may include pseudonymised values regarding visitors„ behaviour, interests or demographic information, such as age or gender. With the help of audience analysis, we can, for example, identify at what times our online service, its functions or content are used most frequently, or invite reuse. It also enables us to understand which areas require optimisation.
In addition to web analytics, we can also use testing methods to test and optimise different versions of our online service or its components, for example.
Unless stated otherwise below, profiles—meaning data compiled into a usage process—may be created for these purposes, and information may be stored in a browser or on an end device and subsequently read out. The collected information includes, in particular, visited websites and elements used there, as well as technical details such as the browser used, the computer system used, and information regarding times of use. If users have consented to the collection of their location data to us or to the providers of the services we use, the processing of location data is also possible.
In addition, the users' IP addresses are stored. However, we use an IP masking procedure (i.e. pseudonymisation by shortening the IP address) to protect users. Generally, no plain user data (such as e-mail addresses or names) are stored in the context of web analytics, A/B testing and optimisation, but rather pseudonyms. This means that neither we nor the providers of the software used know the actual identity of the users, but only the information stored in their profiles for the purpose of the respective procedures.
Information on legal bases: Where we ask users for their consent to the use of third-party providers, the legal basis for processing data is consent. Otherwise, user data is processed on the basis of our legitimate interests (i.e. interest in efficient, economical and recipient-friendly services). In this context, we would also like to draw your attention to the information on the use of cookies in this privacy policy.
- Processed data types: Usage data (e.g. page views and duration of visit, click paths, intensity and frequency of use, types of device and operating systems used, interactions with content and features). Metadata, communication data and procedural data (e.g. IP addresses, timestamps, identification numbers, persons involved).
- Affected persons User (e.g. website visitors, users of online services).
- Purposes of processing and legitimate interests: Audience measurement (e.g. access statistics, recognition of returning visitors); profiles with user-related information (creation of user profiles); provision of our online service and user-friendliness; remarketing; conversion measurement (measuring the effectiveness of marketing measures); marketing; tracking (e.g. interest-based/behavioural profiling, use of cookies). Audience building.
- Storage and deletion: Deletion in accordance with the details in the section „General information on data storage and deletion“. Storage of cookies for up to 2 years (Unless otherwise specified, cookies and similar storage methods may be stored on users' devices for a period of two years.).
- Safety measures: IP Masking (Pseudonymisation of the IP address).
- Legal basis: Consent (Article 6(1)(a) GDPR). Legitimate interests (Article 6(1)(f) GDPR).
Further information on processing operations, procedures and services:
- Google Analytics We use Google Analytics to measure and analyse the use of our online service on the basis of a pseudonymous user identification number. This identification number does not contain any unique data, such as names or email addresses. It is used to assign analysis information to a terminal device in order to recognise which content users have accessed within one or different usage processes, which search terms they have used, whether they have accessed them again or have interacted with our online service. The time of use and its duration are also stored, as are the sources of users who refer to our online service and technical aspects of their terminal devices and browsers.
This involves creating pseudonymous user profiles with information from the use of various devices, for which cookies may be used. Google Analytics does not log or store individual IP addresses for EU users. However, Analytics provides rough geographical location data by deriving the following metadata from IP addresses: city (and the derived latitude and longitude of the city), continent, country, region, sub-continent (and ID-based counterparts). For EU traffic, IP address data is used exclusively for this derivation of geolocation data before being deleted immediately. It is not logged, is not accessible, and is not used for any further purposes. When Google Analytics collects measurement data, all IP lookups are performed on EU-based servers before the traffic is forwarded to Analytics servers for processing; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal basis: Consent (Art. 6 (1) sentence 1 lit. a) GDPR); Website https://marketingplatform.google.com/intl/de/about/analytics/; Safety measures: IP masking (pseudonymisation of the IP address); Privacy policy: https://business.safety.google/privacy/; Data Processing Agreement: https://business.safety.google/adsprocessorterms/; Legal basis for third country transfers: Data Privacy Framework (DPF), standard contractual clauses (https://business.safety.google/adsprocessorterms); Right to object (opt-out): Opt-out plugin: https://tools.google.com/dlpage/gaoptout?hl=de, Advertisement display settings: https://myadcenter.google.com/personalizationoff. Further information: https://business.safety.google/adsservices/ (Types of processing and data processed). - Information on consent recipients and cookieless analysis: Information on consent recipients: The consent given by users within the framework of a consent dialogue (also known as a „cookie opt-in/consent“, ‚cookie banner‘, etc.) serves several purposes. Firstly, it enables us to fulfil our obligation to obtain consent for the storage and reading of information on and from the user's terminal equipment (in accordance with the ePrivacy Directives). Secondly, it covers the processing of users' personal data in accordance with data protection regulations. In addition, this consent also applies to Google, as the company is required under the Digital Markets Act to obtain consent for personalised services. Therefore, we share the status of the consent given by users with Google. Our consent management software informs Google whether consent has been given or not. The aim is to ensure that users' given or refused consent is taken into account when using Google Analytics and when integrating functions and external services. This allows users' consent and their withdrawal of consent to be dynamically adjusted within the scope of Google Analytics and other Google services in our online offering, depending on the user's selection.
Cookieless analysis: We use the advanced implementation of Google Analytics' Consent Mode. This means that if users do not give consent for the storage and reading of information on their end devices – particularly with regard to cookies – no cookies or comparable information will be stored on the users' devices. Similarly, no user profiles will be created.
In this case, Google's code generates a random identification number on the user's device and transmits it to Google (a so-called „ping“). The identification is not stored in the browser, in apps or on other user devices. This identification number is unique to each website visit, meaning that user behavior or interests are not tracked across devices or pages. Only a minimum of information on user activity is sent. This includes details on consent status and information for conversion measurement, i.e. whether a user was directed to our online service by a Google advertisement.
In addition, if available, the following information can be transmitted: a) Function-related information such as headers (technical details transmitted by the browser), b) timestamps (date and time of access), c) user agent (information about the browser and device used, on the web only), d) referrer URL (the URL of the page from which the user arrived), e) aggregated/pseudonymised information: this includes an indication of whether the current or a previous page in the user's navigation history contains information about the ad click in the URL (e.g. GCLID/DCLID, special tracking codes from Google), a random number generated with each page load, and information on the consent management platform used by the website owner (e.g. developer ID); Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal basis: Legitimate interests (Article 6(1)(f) GDPR); Website https://support.google.com/analytics/answer/9976101?hl=de. Privacy policy: https://business.safety.google/privacy/. - Google Tag Manager: We use Google Tag Manager, software by Google that enables us to manage website tags centrally via a user interface. Tags are small code elements on our website that are used to record and analyse visitor activity. This technology helps us to improve our website and the content offered on it. Google Tag Manager itself does not create user profiles, store cookies containing user profiles or carry out independent analyses. Its function is limited to simplifying and making more efficient the integration and management of tools and services that we use on our website. Nevertheless, when using Google Tag Manager, users' IP addresses are transmitted to Google, which is necessary for technical reasons in order to implement the services we use. Cookies may also be set in the process. However, this; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal basis: Consent (Art. 6 (1) sentence 1 lit. a) GDPR); Website https://marketingplatform.google.com; Privacy policy: https://business.safety.google/privacy/; Data Processing Agreement:
https://business.safety.google/adsprocessorterms. Legal basis for third country transfers: Data Privacy Framework (DPF), standard contractual clauses (https://business.safety.google/adsprocessorterms). - HubSpot Tracking Code: The tracking code and tracking pixel collect visitor data, including website activities, IP addresses and online identifiers, in order to monitor website traffic and analyse user behaviour. This data helps to identify visiting companies, attribute visits to known contacts and save information about browsers and devices. The insights gained contribute to the optimisation of the user experience and website performance. The collected data includes the company domain (upon self-identification by filling out a form or registering), IP address, timestamps of visits, visitor ID, page views, clicks and device information. In addition, interactions such as scrolling behaviour, time spent on pages, navigation paths and referring URLs are captured to enable a more precise analysis of user behaviour and detailed insights into visitor journeys. This data is processed on the basis of cookie consent and account settings in order to improve digital services, generate reports on website traffic and interactions, and refine strategies for content optimisation and user engagement. By analysing user behaviour, companies can tailor content specifically, improve conversion rates and optimise marketing measures. In addition, the collection serves to identify returning visits, segment target groups and personalise user experiences based on past interactions. Furthermore, the tracking mechanisms enable companies to track leads and evaluate the effectiveness of marketing campaigns by analysing click-through rates, form submissions and interactions with call-to-action elements. This data helps to optimise strategies, target audiences more precisely and maximise interaction with digital content; Service provider: HubSpot Ireland Limited, Ground Floor, Two Dockland Central, Guild Street, Dublin 1, Ireland; Legal basis: Consent (Art. 6 (1) sentence 1 lit. a) GDPR); Website https://knowledge.hubspot.com/account/how-does-hubspot-track-visitors; Privacy policy: https://legal.hubspot.com/de/privacy-policy; Data Processing Agreement: https://legal.hubspot.com/dpa. Legal basis for third country transfers: Standard Contractual Clauses (https://legal.hubspot.com/dpa).
- Cabin Analytics: For the statistical analysis of the use of our online service and for the creation of regular marketing reports, the marketing agency commissioned by us, Cabin Analytics, is used. In particular, page views, visitor origins, country, browser, device, operating system, language and campaign parameters are analysed. According to the provider, Cabin Analytics does not use cookies, permanent visitor identifiers or fingerprinting. The IP address transmitted for technical reasons is processed in the short term to determine the country of origin and is subsequently not stored. The legal basis is our legitimate interest in the analysis and optimisation of our online service and our marketing measures in accordance with Art. 6 para. 1 sentence 1 lit. f GDPR; Service provider: Nic Mulvaney LTD, 35 Portway, Frome, England, BA11 1QU, United Kingdom; Website https://withcabin.com/. Privacy policy: https://withcabin.com/privacy.
Online marketing
We process personal data for the purpose of online marketing, which may include in particular the marketing of advertising space or the display of advertising and other content (collectively referred to as „content“) based on potential user interests and the measurement of its effectiveness.
For these purposes, so-called user profiles are created and stored in a file (a so-called „cookie“) or similar procedures are used, by means of which information about the user relevant to the display of the aforementioned content is stored. This may include, for example, viewed content, visited websites, online networks used, but also communication partners and technical information such as the browser used, the computer system used, and information on times of use and functions used. If users have consented to the collection of their location data, this may also be processed.
In addition, the users' IP addresses are stored. However, for user protection, we use available IP-masking procedures (i.e., pseudonymisation by shortening the IP address). In general, as part of online marketing procedures, no plain user data (such as e-mail addresses or names) are stored, but rather pseudonyms. This means that neither we nor the providers of the online marketing procedures know the actual user identity, but only the information stored in their profiles.
The statements in the profiles are generally stored in cookies or by means of similar procedures. These cookies can subsequently also be read out on other websites that use the same online marketing procedure and analysed for the purpose of displaying content, as well as being supplemented with further data and stored on the server of the online marketing procedure provider.
By way of exception, it is possible to associate plain text data with the profiles, primarily when users are, for example, members of a social network whose online marketing methods we use and the network links the user profiles with the aforementioned information. We ask you to note that users may make additional arrangements with the providers, such as by giving consent as part of registration.
As a general rule, we only receive access to aggregated information regarding the success of our advertisements. However, as part of what are known as conversion measurements, we can check which of our online marketing methods have led to a conversion, i.e., for example, the conclusion of a contract with us. Conversion measurement is used solely for the purpose of analysing the success of our marketing measures.
Unless otherwise stated, we ask you to assume that deployed cookies are stored for a period of two years.
Notes on Legal Basis: If we ask users for their consent to the use of third-party providers, the legal basis for the processing of data is permission. Otherwise, users' data is processed on the basis of our legitimate interests (i.e. interest in efficient, economical and recipient-friendly services). In this context, we would also like to draw your attention to the information on the use of cookies in this privacy policy.
Information on cancellation and objection:
We refer to the data protection information of the respective providers and the opt-out options provided for them. If no explicit opt-out option has been specified, you have the option, on the one hand, to disable cookies in your browser settings. However, this may restrict the functions of our online services. We therefore additionally recommend the following opt-out options, which are offered comprehensively for the respective regions:
a) Europe: https://youronlinechoices.eu/.
b) Canada: https://youradchoices.ca/.
c) USA: https://optout.aboutads.info/.
d) Cross-regional: https://optout.aboutads.info.
- Processed data types: Usage data (e.g. page views and duration of visit, click paths, intensity and frequency of use, types of device and operating systems used, interactions with content and features). Metadata, communication data and procedural data (e.g. IP addresses, timestamps, identification numbers, persons involved).
- Affected persons User (e.g. website visitors, users of online services).
- Purposes of processing and legitimate interests: Audience measurement (e.g. access statistics, recognition of returning visitors); tracking (e.g. interest-based/behavioural profiling, use of cookies); audience creation; marketing; profiles containing user-related information (creation of user profiles); conversion measurement (measuring the effectiveness of marketing measures); provision of our online service and user-friendliness; remarketing; click tracking.
- Storage and deletion: Deletion in accordance with the details in the section „General information on data storage and deletion“. Storage of cookies for up to 2 years (Unless otherwise specified, cookies and similar storage methods may be stored on users' devices for a period of two years.).
- Safety measures: IP Masking (Pseudonymisation of the IP address).
- Legal basis: Consent (Article 6(1)(a) GDPR). Legitimate interests (Article 6(1)(f) GDPR).
Further information on processing operations, procedures and services:
- Google Ad Manager We use the „Google Ad Manager“ service to place adverts on the Google Display Network (e.g. in search results, in videos, on websites, etc.). Google Ad Manager is characterised by the fact that adverts are displayed in real time based on users’ presumed interests. This enables us to show adverts for our online offering to users who may have a potential interest in our offering or who have previously shown an interest in it, as well as to measure the success of the adverts; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal basis: Legitimate interests (Article 6(1)(f) GDPR); Website https://marketingplatform.google.com; Privacy policy: https://business.safety.google/privacy/; Legal basis for third country transfers: Data Privacy Framework (DPF); Further information: Types of processing and processed data: https://business.safety.google/adsservices/; Google Ads Data Processing Terms: Information regarding services Controller-to-controller data processing terms and standard contractual clauses for third country data transfers: https://business.safety.google/adscontrollerterms. in so far as Google acts as a data processor, data processing terms for Google advertising products and standard contractual clauses for third-country data transfers: https://business.safety.google/adsprocessorterms.
- Google Ads and conversion tracking: Online marketing methods designed to place content and adverts within the service provider’s advertising network (e.g. in search results, in videos, on websites, etc.) so that they are displayed to users who are presumed to have an interest in the adverts. In addition, we measure the conversion rate of the adverts, i.e. whether users have been prompted to interact with the adverts and make use of the advertised offers (so-called ‘conversions’). However, we only receive anonymous information and no personal information about individual users; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal basis: Consent (Art. 6 (1) sentence 1 lit. a) GDPR), Legitimate interests (Art. 6 (1) sentence 1 lit. f) GDPR); Website https://marketingplatform.google.com; Privacy policy: https://business.safety.google/privacy/; Legal basis for third country transfers: Data Privacy Framework (DPF); Further information: Types of processing and processed data: https://business.safety.google/adsservices/. Controller-to-controller data processing terms and standard contractual clauses for third-country data transfers: https://business.safety.google/adscontrollerterms.
- Google Ads Remarketing: Google Remarketing, also known as retargeting, is a technology that allows users of an online service to be added to a pseudonymous remarketing list so that advertisements can be displayed to them on other online platforms based on their visit to the online service; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal basis: Consent (Art. 6 (1) sentence 1 lit. a) GDPR); Website https://marketingplatform.google.com; Privacy policy: https://business.safety.google/privacy/; Legal basis for third country transfers: Data Privacy Framework (DPF); Further information: Types of processing and processed data: https://business.safety.google/adsservices/. Controller-to-controller data processing terms and standard contractual clauses for third-country data transfers: https://business.safety.google/adscontrollerterms.
- LinkedIn Insight Tag: Code that is loaded when a user visits our online service and tracks the user's behaviour and conversions as well as saving them in a profile (potential uses: measurement of campaign performance, optimisation of ad delivery, building of custom and similar target audiences); Service provider: LinkedIn Ireland Unlimited Company, Wilton Plaza, Dublin 2, Ireland; Legal basis: Consent (Art. 6 (1) sentence 1 lit. a) GDPR); Website https://www.linkedin.com; Privacy policy: https://www.linkedin.com/legal/privacy-policy; Data Processing Agreement: https://www.linkedin.com/legal/l/dpa; Legal basis for third country transfers: Data Privacy Framework (DPF), standard contractual clauses (https://www.linkedin.com/legal/l/dpa). Right to object (opt-out): https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.
- UTM Parameter: Analysis of sources and user actions based on the extension of referring web addresses with an additional parameter, the „UTM“ parameter. For example, a UTM parameter such as „utm_source=platformX &utm_medium=video“ can tell us that a person clicked the link on platform X within a video. The UTM parameters provide information about the source of the link, the medium used (e.g. social media, website, newsletter), the type of campaign or the content of the campaign (e.g. posting, link, image and video). With the help of this information, we can, for example, check our visibility on the internet or the effectiveness of our campaigns; Legal basis: Legitimate interests (Article 6(1)(f) GDPR).
- LinkedIn advertising: Placing advertisements within the LinkedIn platform and evaluating the campaign results; Service provider: LinkedIn Ireland Unlimited Company, Wilton Plaza, Dublin 2, Ireland; Legal basis: Consent (Art. 6 (1) sentence 1 lit. a) GDPR), Legitimate interests (Art. 6 (1) sentence 1 lit. f) GDPR); Website https://business.linkedin.com/de-de/marketing-solutions/ads; Privacy policy: https://www.linkedin.com/legal/privacy-policy; Data Processing Agreement: https://www.linkedin.com/legal/l/dpa; Legal basis for third country transfers: Data Privacy Framework (DPF), standard contractual clauses (https://de.linkedin.com/legal/l/dpa); Right to object (opt-out): https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out. Further information: https://www.linkedin.com/legal/l/dpa.
- HubSpot Marketing Hub email marketing, lead generation, marketing automation, analysis of campaign performance, management of social media interactions, creation and optimisation of landing pages as well as contact management; Service provider: HubSpot Ireland Limited, Ground Floor, Two Dockland Central, Guild Street, Dublin 1, Ireland; Legal basis: Consent (Art. 6 (1) sentence 1 lit. a) GDPR); Website https://www.hubspot.de; Privacy policy: https://legal.hubspot.com/de/privacy-policy; Data Processing Agreement: https://legal.hubspot.com/dpa. Legal basis for third country transfers: Data Privacy Framework (DPF), standard contractual clauses (https://legal.hubspot.com/dpa).
Customer reviews and rating procedures
We take part in review and rating procedures in order to evaluate, optimise and promote our services. If users rate us via the participating review platforms or procedures or otherwise provide feedback, the general terms and conditions or terms of use and the data protection notices of the respective providers shall also apply. As a rule, leaving a review also requires registration with the respective providers.
To ensure that the reviewers have actually used our services, we transmit the data required for this purpose regarding the customer and the service used (including name, email address and order number or article number) to the respective review platform with the customer's consent. This data is used solely to verify the authenticity of the user.
- Processed data types: Contract data (e.g. subject matter of the contract, term, customer category); usage data (e.g. page views and dwell time, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and functions). Meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, persons involved).
- Affected persons Beneficiaries and clients. Users (e.g. website visitors, users of online services).
- Purposes of processing and legitimate interests: Feedback (e.g. collecting feedback via online form). Marketing.
- Legal basis: Legitimate interests (Article 6(1)(f) GDPR).
Further information on processing operations, procedures and services:
- Google Customer Reviews: Service for collecting and/or displaying customer satisfaction and customer feedback; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal basis: Legitimate interests (Article 6(1)(f) GDPR); Website https://www.google.com/; Privacy policy: https://business.safety.google/privacy/; Legal basis for third country transfers: Data Privacy Framework (DPF); Further information: As part of gathering customer reviews, an identification number and the time of the transaction to be reviewed are processed, along with the customer's email address and their country of residence for review requests sent directly to customers, as well as the review details themselves; further details on the types of processing and the data processed: https://business.safety.google/adsservices/. Google Ads Data Processing Terms: Information on Services Controller-Controller Data Processing Terms and Standard Contractual Clauses for transfers of data to third countries: https://business.safety.google/adscontrollerterms.
- kununu Provision and display of employer reviews (reviews of companies by employees), publication of reports on working conditions, management of user accounts, provision of a search function for company profiles; Service provider: kununu GmbH, Kurfürstenstr. 1, 80801 Munich, Germany; Legal basis: Legitimate interests (Article 6(1)(f) GDPR); Website https://www.kununu.com/. Privacy policy: https://www.kununu.com/de/info/datenschutz.
- OMR Reviews: We use OMR Reviews as a review platform for our products and services. Users can submit reviews there regarding their experiences with our offerings, either on their own initiative or following an invitation. OMR Reviews checks submitted reviews and publishes them on the respective vendor profile once successfully verified. We use the reviews published there to display customer feedback and to improve our offerings. The legal basis for our participation in the review process and the use of published reviews is our legitimate interest in the transparent presentation of customer experiences, quality assurance, and the improvement of our products and services in accordance with Art. 6(1)(1)(f) GDPR. To the extent that we directly invite individuals to submit a review and transmit personal data to OMR Reviews for this purpose, this is done solely on the basis of a relevant legal basis.; Service provider: Software Reviews GmbH, Lagerstraße 36, 20357 Hamburg, Germany; Website https://omr.com/de/reviews. Privacy policy: https://omr.com/de/datenschutz.
social media presences
We maintain online presences within social networks and in this context process user data in order to communicate with the users active there or to offer information about ourselves.
We would like to point out that user data may be processed outside the European Union in the process. This may result in risks for users, as it could, for example, make the enforcement of user rights more difficult.
Furthermore, user data within social networks is generally processed for market research and advertising purposes. For example, user profiles can be created based on user behaviour and the resulting interests of the users. The latter may in turn be used, for instance, to display advertisements inside and outside the networks that presumably correspond to the interests of the users. Therefore, cookies are generally stored on the users' computers, in which the users' behaviour and interests are saved. In addition, data can also be stored in the user profiles independently of the devices used by the users (in particular if they are members of the respective platforms and logged in there).
For a detailed description of the respective forms of processing and the options for objection (opt-out), we refer to the data privacy policies and information provided by the operators of the respective networks.
We also point out that in the case of requests for information and the assertion of data subject rights, these can be asserted most effectively with the providers. Only the latter have access to the respective user data and can directly take appropriate measures and provide information. Should you nevertheless require assistance, you can contact us.
- Processed data types: Contact data (e.g. postal and email addresses or telephone numbers); content data (e.g. textual or visual messages and posts as well as information relating to them, such as details on authorship or time of creation); usage data (e.g. page views and dwell time, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions).
- Affected persons User (e.g. website visitors, users of online services).
- Purposes of processing and legitimate interests: Communication; feedback (e.g., collecting feedback via online form). Public relations.
- Storage and deletion: Erasure in accordance with the details in the section „General Information on Data Storage and Erasure“.
- Legal basis: Legitimate interests (Article 6(1)(f) GDPR).
Further information on processing operations, procedures and services:
- Instagram: Social network, enabling the sharing of photos and videos, commenting on and favouriting posts, sending messages, and subscribing to profiles and pages; Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Legal basis: Legitimate interests (Article 6(1)(f) GDPR); Website https://www.instagram.com; Privacy policy: https://privacycenter.instagram.com/policy/. Legal basis for third country transfers: Data Privacy Framework (DPF).
- Facebook pages: Profiles within the social network Facebook – The controller is jointly responsible with Meta Platforms Ireland Limited for the collection and transmission of data of visitors to our Facebook page („fan page“). This includes in particular information on user behaviour (e.g. content viewed or interacted with, actions performed) and device information (e.g. IP address, operating system, browser type, language settings, cookie data). Further details on this can be found in the Facebook Data Policy: https://www.facebook.com/privacy/policy/. Facebook also uses this data to provide us with statistical evaluations via the „Page Insights“ service, which provide information on how people interact with our page and its content. The basis for this is an agreement with Facebook („Page Insights Information“: https://www.facebook.com/legal/terms/page_controller_addendum), which regulates, among other things, security measures and the exercise of data subjects' rights. Further information can be found here: https://www.facebook.com/legal/terms/information_about_page_insights_data. Users can therefore direct requests for information or deletion straight to Facebook. Users' rights (in particular access, erasure, objection, lodging a complaint with a supervisory authority) remain unaffected by this. Joint responsibility is limited exclusively to the collection of data by Meta Platforms Ireland Limited (EU). Meta Platforms Ireland Limited is solely responsible for any further processing, including any transmission to Meta Platforms Inc. in the USA; Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Legal basis: Legitimate interests (Article 6(1)(f) GDPR); Website https://www.facebook.com; Privacy policy: https://www.facebook.com/privacy/policy/. Legal basis for third country transfers: Data Privacy Framework (DPF), standard contractual clauses (https://www.facebook.com/legal/EU_data_transfer_addendum).
- LinkedIn: Social network – We, together with LinkedIn Ireland Unlimited Company, are responsible for the collection (but not the further processing) of data from visitors used to create the „Page Insights“ (statistics) of our LinkedIn profiles. This data includes information about the types of content users view or interact with, as well as the actions they take. In addition, details about the devices used, such as IP addresses, operating system, browser type, language settings and cookie data, as well as information from user profiles, such as job function, country, industry, seniority, company size and employment status, are recorded. Data protection information regarding the processing of user data by LinkedIn can be found in LinkedIn's privacy policy: https://www.linkedin.com/legal/privacy-policy.
We have entered into a special agreement with LinkedIn Ireland (the „Page Insights Joint Controller Addendum“, https://legal.linkedin.com/pages-joint-controller-addendum), which governs in particular the security measures that LinkedIn must observe and in which LinkedIn has agreed to fulfil the rights of data subjects (i.e. users can, for example, send requests for information or deletion directly to LinkedIn). The rights of users (in particular the right to information, deletion, objection and complaint to the competent supervisory authority) are not restricted by the agreements with LinkedIn. Joint controllership is limited to the collection and transmission of data to LinkedIn Ireland Unlimited Company, a company based in the EU. Any further processing of the data is the sole responsibility of LinkedIn Ireland Unlimited Company, particularly with regard to the transfer of data to the parent company, LinkedIn Corporation, in the USA; Service provider: LinkedIn Ireland Unlimited Company, Wilton Plaza, Dublin 2, Ireland; Legal basis: Legitimate interests (Article 6(1)(f) GDPR); Website https://www.linkedin.com; Privacy policy: https://www.linkedin.com/legal/privacy-policy; Legal basis for third country transfers: Data Privacy Framework (DPF), standard contractual clauses (https://www.linkedin.com/legal/privacy-policy). Right to object (opt-out): https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out. - X Social network; Service provider: X Internet Unlimited Company, One Cumberland Place, Fenian Street, Dublin 2 D02 AX07, Ireland; Legal basis: Legitimate interests (Article 6(1)(f) GDPR); Website https://x.com. Privacy policy: https://x.com/de/privacy.
- YouTube Social network and video platform; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal basis: Legitimate interests (Article 6(1)(f) GDPR); Privacy policy: https://business.safety.google/privacy/; Legal basis for third country transfers: Data Privacy Framework (DPF). Right to object (opt-out): https://myadcenter.google.com/.
- Star Social network; Service provider: New Work SE, Am Strandkai 1, 20457 Hamburg, Germany; Legal basis: Legitimate interests (Article 6(1)(f) GDPR); Website https://www.xing.com/. Privacy policy: https://privacy.xing.com/de/datenschutzerklaerung.
Plug-ins and embedded functions as well as content
We integrate functional and content elements into our online services which are obtained from the servers of their respective providers (hereinafter referred to as „third-party providers“). These may include, for example, graphics, videos or city maps (hereinafter uniformly referred to as „content“).
The inclusion always requires that the third-party providers of this content process the users„ IP address, as without an IP address they could not send the content to their browser. The IP address is therefore necessary for the display of this content or functions. We endeavour only to use content whose respective providers use the IP address solely for the delivery of the content. Third-party providers may also use so-called pixel tags (invisible graphics, also referred to as “web beacons„) for statistical or marketing purposes. The “pixel tags" can be used to evaluate information such as visitor traffic on the pages of this website. The pseudonymous information can also be stored in cookies on the user's device and can contain, amongst other things, technical information on the browser and operating system, referring websites, the time of the visit as well as further details on the use of our online service, and can also be combined with such information from other sources.
Notes on Legal Basis: If we ask users for their consent to the use of third-party providers, the legal basis for the processing of data is permission. Otherwise, user data is processed on the basis of our legitimate interests (i.e. interest in efficient, economical and recipient-friendly services). In this context, we would also like to draw your attention to the information on the use of cookies in this privacy policy.
- Processed data types: Usage data (e.g. page views and duration of visit, click paths, intensity and frequency of use, types of device and operating systems used, interactions with content and features). Metadata, communication data and procedural data (e.g. IP addresses, timestamps, identification numbers, persons involved).
- Affected persons User (e.g. website visitors, users of online services).
- Purposes of processing and legitimate interests: Provision of our online services and user-friendliness; audience measurement (e.g. access statistics, recognition of returning visitors); tracking (e.g. interest-based/behavioural profiling, use of cookies); creation of target groups; marketing.
- Storage and deletion: Deletion in accordance with the details in the section „General information on data storage and deletion“. Storage of cookies for up to 2 years (Unless otherwise specified, cookies and similar storage methods may be stored on users' devices for a period of two years.).
- Legal basis: Consent (Article 6(1)(a) GDPR). Legitimate interests (Article 6(1)(f) GDPR).
Further information on processing operations, procedures and services:
- reCAPTCHA: We integrate the „reCAPTCHA“ function to be able to recognise whether entries (e.g. in online forms) are made by humans and not by automatically operating machines (so-called „bots“). The data processed may include IP addresses, information on operating systems, devices or browsers used, language settings, location, mouse movements, keystrokes, length of stay on websites, previously visited websites, interactions with reCAPTCHA on other websites, cookies under certain circumstances, and results of manual recognition processes (e.g. answering questions or selecting objects in images). Data processing is carried out on the basis of our legitimate interest in protecting our online offering from abusive automated crawling and spam; legal bases: use to protect our forms from automated input, abuse and spam. The legal basis is our legitimate interest in the security and functionality of our online offerings in accordance with Art. 6 para. 1 sentence 1 lit. f GDPR. Insofar as information is stored on the terminal device or accessed from it, this is done, to the extent technically necessary, on the basis of § 25 para. 2 no. 2 TDDDG; standard contractual clauses: https://cloud.google.com/terms/sccs/eu-c2p; data processing agreement: https://cloud.google.com/terms/data-processing-addendum; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Website https://cloud.google.com/security/products/recaptcha. Privacy policy: https://business.safety.google/privacy/.
- YouTube videos: Video content; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal basis: Consent (Art. 6 (1) sentence 1 lit. a) GDPR); Website https://www.youtube.com; Privacy policy: https://business.safety.google/privacy/; Legal basis for third country transfers: Data Privacy Framework (DPF). Right to object (opt-out): Opt-out plugin: https://tools.google.com/dlpage/gaoptout?hl=de, Advertisement display settings: https://myadcenter.google.com/personalizationoff.
Processing of data in the context of employment relationships
As part of employment relationships, personal data is processed with the aim of effectively establishing, implementing and terminating such relationships. This data processing supports various operational and administrative functions necessary for the management of employee relations.
This involves data processing across various aspects, ranging from the initiation of the contract to its termination. This includes the organisation and management of daily working hours, the administration of access rights and permissions, as well as the handling of staff development measures and performance reviews. The processing also serves payroll accounting and the management of wage and salary payments, which represent critical aspects of contract performance.
Additionally, data processing takes into account legitimate interests of the data-controlling employer, such as ensuring workplace safety or recording performance data for the evaluation and optimisation of operational processes. Furthermore, data processing includes the disclosure of employee data in the context of external communication and publication processes, where this is necessary for operational or legal purposes.
The processing of this data is always carried out in compliance with the applicable legal framework, with the objective always being the creation and maintenance of a fair and efficient working environment. This also includes taking into account the data protection of the employees concerned, the anonymisation or deletion of data after the purpose of processing has been fulfilled or in accordance with statutory retention periods.
- Processed data types: Employment data (information regarding employees and other individuals in an employment relationship); payment data (e.g. bank details, invoices, payment history); contract data (e.g. subject matter of the contract, term, customer category); master data (e.g. full name, residential address, contact information, customer number, etc.); contact data (e.g. postal and email addresses or telephone numbers); content data (e.g. textual or visual messages and posts as well as information relating to them, such as details on authorship or time of creation); social security data (data subject to social secrecy and processed, for example, by social security institutions, social welfare authorities or welfare agencies); log data (e.g. log files concerning logins or the retrieval of data or access times); performance and behavioural data (e.g. performance and behavioural aspects such as performance evaluations, feedback from superiors, training participation, compliance with company guidelines, self-assessments and behavioural assessments); working time data (e.g. start of working hours, end of working hours, actual working hours, target working hours, break times, overtime, days of annual leave, special leave days, sick days, days of absence, home office days, business trips); salary data (e.g. base salary, bonus payments, premiums, tax bracket information, allowances for night work/overtime, tax deductions, social security contributions, net payout amount); usage data (e.g. page views and dwell time, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and functions); image and/or video recordings (e.g. photographs or video recordings of a person); meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, persons involved).
- Special categories of personal data: Health data; religious or philosophical beliefs. Trade union membership.
- Affected persons Workers (e.g. employees, applicants, temporary staff and other staff members). Business and contractual partners.
- Purposes of processing and legitimate interests: Establishment and implementation of employment relationships (processing of employee data in the context of the establishment and implementation of employment relationships); business processes and operating procedures; provision of contractual services and fulfilment of contractual obligations; office and organisational procedures; public relations. Security measures.
- Legal basis: Performance of a contract and pre-contractual enquiries (Article 6(1)(b) UK GDPR); Legal obligation (Article 6(1)(c) UK GDPR); Legitimate interests (Article 6(1)(f) UK GDPR). Processing of special categories of personal data relating to healthcare, occupation and social security (Article 9(2)(h) UK GDPR).
Further information on processing operations, procedures and services:
- Time and attendance tracking: Procedures for recording employees' working hours include both manual and automated methods, such as the use of time clocks, time-tracking software or mobile apps. Activities carried out include entering clock-in and clock-out times, break times, overtime and absences. The verification and validation of recorded working hours involves cross-checking with roster or shift schedules, checking for time off and the approval of overtime by line managers. Reports and analyses are generated on the basis of the recorded working hours to provide timesheets, overtime reports and absence statistics for management and the Human Resources department; Legal basis: Performance of a contract and pre-contractual enquiries (Art. 6(1)(b) GDPR), Legitimate interests (Art. 6(1)(f) GDPR).
- Access rights management: Processes required for the definition, management and control of access rights and user roles within a system or organisation (e.g. creation of permission profiles, role- and access-based control, review and approval of access requests, regular review of access rights, tracking and auditing of user activities, creation of security policies and procedures); Legal basis: Performance of a contract and pre-contractual enquiries (Article 6(1)(b) GDPR), Legal obligation (Article 6(1)(c) GDPR), Legitimate interests (Article 6(1)(f) GDPR).
- Special categories of personal data: Special categories of personal data are processed within the employment relationship or for the fulfilment of legal obligations. The processed special categories of personal data include data concerning employees' health, trade union membership or religious affiliation. These data may, for example, be forwarded to health insurance funds or processed for the assessment of employees' ability to work or for occupational health management or for details to be provided to the tax office; Legal basis: Performance of a contract and pre-contractual enquiries (Article 6(1)(b) GDPR), Legal obligation (Article 6(1)(c) GDPR), Legitimate interests (Article 6(1)(f) GDPR).
- Sources of the processed data: Personal data obtained in the context of the employees' application and/or employment relationship is processed. In addition, where required by law, personal data is collected from other sources. These may include tax authorities for tax-relevant information, the respective health insurance fund for information on incapacity to work, third parties such as employment agencies, or publicly accessible sources such as professional social networks as part of the application process.; Legal basis: Legal obligation (Art. 6(1)(c) GDPR), Legitimate interests (Art. 6(1)(f) GDPR).
- Purposes of data processing: The personal data of employees are processed primarily for the establishment, performance and termination of the employment relationship. Furthermore, the processing of this data is necessary to comply with statutory obligations in the field of tax and social security law. In addition to these primary purposes, employee data is also used to fulfil regulatory and supervisory requirements, to optimise electronic data processing procedures and to compile internal or cross-company data, potentially including statistical data. Furthermore, employee data may be processed for the assertion of legal claims and for defence in legal disputes; Legal basis: Performance of a contract and pre-contractual enquiries (Article 6(1)(b) GDPR), Legal obligation (Article 6(1)(c) GDPR), Legitimate interests (Article 6(1)(f) GDPR).
- Transmission of employee data: Employee data is processed internally only by those departments that require it to fulfil operational, contractual and legal obligations.
The transfer of data to external recipients only takes place if this is required by law, or if the employees concerned have given their consent. Possible scenarios for this may be requests for information from authorities or the existence of capital-forming benefits. Furthermore, the controller may forward personal data to other recipients, insofar as this is necessary to fulfil their contractual and legal obligations as an employer. These recipients may include: a) Banks b) Health insurance funds, pension insurance providers, occupational pension providers and other social security providers c) Authorities, courts (e.g. tax authorities, labour courts, other supervisory authorities within the scope of fulfilling reporting and information obligations) d) Tax advisors and legal counsel e) Third-party debtors in the case of wage and salary garnishments f) Other bodies to which legally binding declarations must be made.
Furthermore, data may be passed on to third parties if this is necessary for communication with business partners, suppliers or other service providers. Examples of this include details in the sender section of emails or letterheads, as well as the creation of profiles on external platforms; Legal basis: Performance of a contract and pre-contractual enquiries (Art. 6(1)(b) GDPR), Legitimate interests (Art. 6(1)(f) GDPR). - Business travel and travel expenses: procedures required for the planning, execution and settlement of business trips (e.g. booking travel, organising accommodation and transport, managing travel advances, submitting and reviewing expense claims, controlling and recording incurred costs, compliance with travel policies, management of travel expense processing); Legal basis: Performance of a contract and pre-contractual enquiries (Article 6(1)(b) GDPR), Legal obligation (Article 6(1)(c) GDPR), Legitimate interests (Article 6(1)(f) GDPR).
- Payroll and wage accounting: procedures required for the calculation, payment and documentation of salaries, wages and other employee remuneration (e.g. recording of working hours, calculation of deductions and allowances, remittance of taxes and social security contributions, preparation of payslips, maintenance of payroll accounts, reporting to the tax office and social security authorities); Legal basis: Performance of a contract and pre-contractual requests (Art. 6(1)(b) GDPR), Legal obligation (Art. 6(1)(c) GDPR).
- Deletion of employee data: Employee data is deleted under German law if it is no longer required for the purpose for which it was collected, unless it has to be retained or archived due to legal obligations or the employer's interests. In doing so, the following retention and archiving obligations are observed:
- General HR records – General HR records (such as employment contracts, references, supplementary agreements) are kept for up to three years after the termination of the employment relationship (§ 195 BGB).
Tax-relevant documents – Tax-relevant documents in the personnel file are kept for six years (§ 147 AO, § 257 HGB).
Information on remuneration and working hours – Information on remuneration and working hours for (accident) insured persons with proof of earnings is kept for five years (§ 165 I 1, IV 2 SGB VII). - Payroll lists including lists for special payments – payroll lists including lists for special payments, provided that a booking voucher exists, must be retained for ten years (§ 147 AO, § 257 HGB).
- Payroll sheets for interim, final and special payments – payroll sheets for interim, final and special payments are kept for six years (§ 147 AO, § 257 HGB).
- Documents relating to employee insurance – Documents relating to employee insurance, insofar as accounting vouchers are available, shall be kept for ten years (§ 147 AO, § 257 HGB).
- Contribution statements to social security institutions – Contribution statements to social security institutions are retained for ten years (§ 165 SGB VII).
Payroll accounts – Payroll accounts must be kept for six years (§ 41 I 9 EStG). - Applicant data – Retained for a maximum of six months from receipt of the rejection.
- Working time records (for more than 8 hours on working days) – Retained for two years (§ 16 II Working Hours Act (ArbZG)).
- Application documents (following online job advertisement) – Kept for three to a maximum of six months after receipt of the rejection (§ 26
- Federal Data Protection Act (BDSG) new version, section 15 (4) of the General Equal Treatment Act (AGG).
- Certificates of incapacity for work (AU) – Are kept for up to five years (§ 6 I Act on Equalisation of Employers' Aufwendungen (AAG)).
- Documents relating to occupational pension schemes – Retained for 30 years (Section 18a of the Occupational Pensions Act (BetrAVG)).
- Employee sickness data – Kept for twelve months from the start of the illness if the absence does not exceed six weeks in a year.
- Documents relating to maternity leave – Retained for two years (§ 27 para. 5 MuSchG).
- General HR records – General HR records (such as employment contracts, references, supplementary agreements) are kept for up to three years after the termination of the employment relationship (§ 195 BGB).
- Personnel record management: Processes required for the organisation, updating and management of employee data and records (e.g. recording of master personnel data, retention of employment contracts, references and certificates, updating of data in the event of changes, compilation of documents for employee reviews, archiving of personnel files, compliance with data protection regulations); Legal basis: Performance of a contract and pre-contractual enquiries (Art. 6(1)(b) GDPR), Legal obligation (Art. 6(1)(c) GDPR), Legitimate interests (Art. 6(1)(f) GDPR), Processing of special categories of personal data relating to healthcare, occupation and social security (Art. 9(2)(h) GDPR).
- Staff development, performance appraisal and annual reviews: procedures required in the fields of employee development and advancement, performance assessment, and appraisals (e.g. training needs analysis, planning and implementation of training measures, preparation of performance appraisals, conducting target-setting and feedback meetings, career planning and talent management, succession planning); Legal basis: Performance of a contract and pre-contractual enquiries (Art. 6(1)(b) GDPR), Legal obligation (Art. 6(1)(c) GDPR), Legitimate interests (Art. 6(1)(f) GDPR), Processing of special categories of personal data relating to healthcare, occupation and social security (Art. 9(2)(h) GDPR).
- Obligation to provide data: The controller points out to the employees that the provision of their data is required. This is generally the case if the data is necessary for the establishment and performance of the employment relationship or if its collection is required by law. The provision of data may also be required if employees assert claims or if claims are due to the employees. The implementation of these measures or fulfilment of benefits depends on the provision of this data (for example, the provision of data for the purpose of receiving wages); Legal basis: Performance of a contract and pre-contractual enquiries (Article 6(1)(b) GDPR), Legal obligation (Article 6(1)(c) GDPR), Legitimate interests (Article 6(1)(f) GDPR).
- Publication and disclosure of employee data: Staff data will only be published or disclosed to third parties if, firstly, this is necessary for the performance of work duties in accordance with the employment contract. This applies, for example, if employees are named as contact persons in correspondence, on the website or in public registers by agreement or in accordance with an agreed job description, or if the scope of duties includes representative functions. Likewise, this may be the case if representation or communication with the public takes place as part of the performance of duties, such as photographic images in the context of public relations work. Otherwise, employee data will only be published with their consent or on the basis of legitimate interests of the employer, for example in the case of stage or group photographs taken during a public event; Legal basis: Performance of a contract and pre-contractual enquiries (Art. 6(1)(b) GDPR), Legitimate interests (Art. 6(1)(f) GDPR).
Application process
The application process requires applicants to provide us with the data necessary for their assessment and selection. What information is required is apparent from the job description or, in the case of online forms, from the details provided there.
Generally, the required details include personal information such as name, address, and contact details, as well as proof of the qualifications necessary for a position. Upon request, we are also happy to provide information on which specific details are required.
Where available, applicants are welcome to submit their applications via our online form, which is encrypted using state-of-the-art technology. Alternatively, it is also possible to send applications to us by email. However, we would like to point out that emails are generally not sent in an encrypted format on the internet. Although emails are usually encrypted in transit, this does not happen on the servers from which they are sent and received. Therefore, we cannot accept responsibility for the security of the application during its transmission between the sender and our server.
For the purposes of applicant searching, submitting applications, and selecting applicants, we may use applicant management or recruitment software and platforms, as well as services from third parties, in compliance with statutory requirements.
Applicants are welcome to contact us regarding the method of submitting their application or to send us their application by post.
Processing of special categories of data: Insofar as special categories of personal data (Art. 9(1) GDPR, e.g., health data such as severely disabled status or ethnic origin) are requested from applicants or communicated by them within the scope of the application procedure, their processing is carried out so that the controller or the data subject can exercise their rights deriving from employment law and the law of social security and social protection and fulfil their obligations in this regard, in the case of the protection of the vital interests of the applicant or other persons, or for the purposes of preventive medicine or occupational medicine, for the assessment of the employee's working capacity, for medical diagnosis, for the provision of care or treatment in the health or social sector, or for the management of health or social care systems and services.
Deletion of data: In the event of a successful application, the data provided by applicants may be further processed by us for the purposes of the employment relationship. Otherwise, if the application for a job vacancy is unsuccessful, the applicants' data will be deleted. The applicants' data will also be deleted if an application is withdrawn, which applicants are entitled to do at any time. Subject to a justified revocation by the applicants, the data will be deleted no later than six months after expiry, so that we can answer any follow-up questions regarding the application and meet our burden of proof under the regulations on the equal treatment of applicants. Invoices for any reimbursement of travel expenses will be archived in accordance with tax law requirements.
Included in an applicant pool: Inclusion in an applicant pool, if offered, is based on consent. Applicants are informed that their consent to be included in the talent pool is voluntary, has no influence on the ongoing application process and that they can withdraw their consent at any time with future effect.
Duration of data retention in the applicant pool in months: Three
- Processed data types: Master data (e.g. full name, residential address, contact information, customer number, etc.); contact data (e.g. postal and email addresses or telephone numbers); content data (e.g. text or image messages and posts as well as information relating to them, such as details on authorship or time of creation). Applicant data (e.g. personal details, postal and contact addresses, documents belonging to the application and the information contained therein, such as cover letters, CVs, references as well as further information on their person or qualifications communicated with regard to a specific position or voluntarily by applicants).
- Affected persons Applicant.
- Purposes of processing and legitimate interests: Application procedure (justification and any subsequent conduct as well as possible subsequent termination of the employment relationship).
- Storage and deletion: Erasure in accordance with the details in the section „General Information on Data Storage and Erasure“.
- Legal basis: Application procedure as a pre-contractual or contractual relationship (Art. 6(1)(b) GDPR). Legitimate interests (Art. 6(1)(f) GDPR).
Further information on processing operations, procedures and services:
- LinkedIn Recruiter: Job search and application-related services within the LinkedIn platform; Service provider: LinkedIn Ireland Unlimited Company, Wilton Plaza, Dublin 2, Ireland; Legal basis: Legitimate interests (Article 6(1)(f) GDPR); Website https://www.linkedin.com; Privacy policy: https://www.linkedin.com/legal/privacy-policy; Data Processing Agreement: https://www.linkedin.com/legal/l/dpa. Legal basis for third country transfers: Data Privacy Framework (DPF), standard contractual clauses (https://www.linkedin.com/legal/l/dpa).
Privacy information for whistleblowers
In this section, you will find information on how we handle data of persons who provide tips (whistleblowers), as well as of affected and involved parties within the scope of our whistleblowing procedure. Our goal is to provide a straightforward and secure way to report potential misconduct by us, our employees or service providers, in particular for actions that violate laws or ethical guidelines. In addition, we ensure appropriate processing and handling of the reports.
- Processed data types: Master data (e.g. full name, residential address, contact information, customer number, etc.); employee data (information on employees and other persons in an employment relationship); contact data (e.g. postal and email addresses or telephone numbers); content data (e.g. textual or visual messages and posts as well as information relating to them, such as details on authorship or time of creation). Usage data (e.g. page views and dwell time, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions).
- Affected persons Beneficiaries and clients; employees (e.g. staff, applicants, temporary workers and other personnel); third parties. Whistleblowers.
- Purposes of processing and legitimate interests: Whistleblower protection.
- Storage and deletion: Erasure in accordance with the details in the section „General Information on Data Storage and Erasure“.
- Legal basis: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR); Legal obligation (Art. 6 para. 1 sentence 1 lit. c) GDPR). Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
Further information on processing operations, procedures and services:
- Legal bases (Germany): Insofar as we process data to fulfil our statutory obligations in accordance with the Whistleblower Protection Act (HinSchG), the legal basis for the processing is Article 6(1) sentence 1 lit. c) GDPR and, in the case of special categories of personal data, Article 9(2) lit. g) GDPR, section 22 of the Federal Data Protection Act (BDSG), in each case in conjunction with section 10 of the HinSchG. This relates to the obligation to set up and operate an internal whistleblower reporting office, the fulfilment of its statutory duties and, in the event of the use of the data collected in the reporting procedure, the initiation of further investigations or employment law measures against persons who have been found to have committed a breach.
Insofar as we process data (particularly in the event of established misconduct) as part of or in preparation for legal defence, this is done on the basis of our legitimate interests in lawful and ethical conduct in accordance with Article 6(1)(1)(f) of the GDPR.
Insofar as you have given us consent to the processing of personal data for specific purposes, the processing is carried out on this basis pursuant to Art. 6 para. 1 sentence 1 lit. a) GDPR and, in the case of special categories of personal data, Art. 9 para. 2 lit. a) GDPR. An example of this would be the disclosure of the whistleblower's identity or the making of a verbatim transcript during an in-person meeting. Consent that has been given may be revoked at any time with effect for the future. - Processed data types:
As part of receiving and processing reports and in the subsequent whistleblowing procedure, we may collect various data. In particular, this includes data provided by a whistleblower, such as:
- Name, contact details and whereabouts of the person providing the tip,
- Names and details of potential witnesses or persons affected by the tip-off,
- Names and details of the persons to whom the report relates,
- Data concerning the alleged misconduct,
- Further relevant details, provided the whistleblower shared them.
For the purposes of establishing the facts and for further proceedings, we also process the following personal data:
- Unique identification of the notification,
- Contact details of the whistleblower, if provided,
- Personal data of persons mentioned in the tip, if provided,
- Personal data of individuals indirectly affected by the fact-finding process, where applicable,
- Personal data of individuals from other participating companies (e.g. in the context of legal advice), if relevant,
- Further data relating to the matter.
As part of receiving and processing reports and in the subsequent whistleblowing procedure, we may collect various data. In particular, this includes data provided by a whistleblower, such as:
- Name, contact details and whereabouts of the person providing the tip,
- Names and details of potential witnesses or persons affected by the tip-off,
- Names and details of the persons to whom the report relates,
- Data concerning the alleged misconduct,
- Further relevant details, provided the whistleblower shared them.
For the purposes of establishing the facts and for further proceedings, we also process the following personal data:
- Unique identification of the notification,
- Contact details of the whistleblower, if provided,
- Personal data of persons mentioned in the tip, if provided,
- Personal data of individuals indirectly affected by the fact-finding process, where applicable,
- Personal data of individuals from other participating companies (e.g. in the context of legal advice), if relevant,
- Further data relating to the matter.
- Special categories of personal data:
It may happen that, as part of our activities, we collect special categories of personal data, particularly when these are provided by a whistleblower. These include:
- A person's health-related data,
- data concerning the racial or ethnic origin of persons,
- Information about a person's religious or philosophical beliefs,
- Information regarding a person's sexual orientation.
These data will only be processed if they are relevant to the handling of the respective report and have been expressly provided by the whistleblower.
. - Use of our online forms: Please note that it is possible to submit reports anonymously. To ensure the security of your data when using our online forms, we recommend accessing them in your browser's ‚incognito mode‘. Here is how you can open an incognito window: a) On a Windows PC: Open your browser and press Ctrl+Shift+N; b) On a Mac: Open your browser and press Command+Shift+N; c) On mobile devices: Switch to private mode via the tab menu.
When accessing our website in normal mode, your browser automatically sends certain information to our server, such as browser type and version, and the date and time of your access. This also includes the IP address of your device. These data are temporarily stored in a log file and automatically deleted after a maximum of 30 days.
The processing of the IP address serves technical and administrative purposes for establishing the connection to our website. It ensures the security, stability, and functionality of the whistleblowing form and is an important component of our measures to ensure the confidential submission of reports.
The processing of the logged data is based on Article 6(1) sentence 1 lit. f) GDPR. Our legitimate interest lies in the need for security and the necessity to ensure the technical prerequisites for a smooth and trouble-free submission of reports; Legal basis: Legitimate interests (Article 6(1)(f) GDPR). - Provision of names: You have the option to submit tips anonymously. However, unless prohibited by national legislation, we recommend providing your name and contact details. This enables us to investigate the report more effectively and, if necessary, contact you directly.
If you provide your name and contact details, your identity will be treated in strict confidence. Exceptions to this confidentiality only exist if we are legally obliged to disclose your identity. This may be necessary to protect or defend our rights or the rights of our employees, customers, suppliers or business partners. A further exception applies if it is determined that the allegations were made with malicious intent. - Provision of data to third parties: We will only disclose data relating to the reports submitted to third parties under certain circumstances. This will occur either a) if you have given us your express consent to do so, or b) if there is a legal obligation to disclose the data. Potential third parties include public authorities, government bodies, regulatory bodies or tax authorities, where disclosure is necessary to fulfil a legal or regulatory obligation. Furthermore, we may engage solicitors and other specialist advisers in accordance with legal provisions. They are authorised to investigate suspected misconduct and to take any necessary action following an investigation, such as initiating disciplinary or legal proceedings. In addition, service providers carefully selected and monitored by us may receive data for these purposes (for example, operators of a web-based reporting system). However, these service providers are contractually obliged, within the framework of a data processing agreement, to comply with the applicable data protection regulations.
- Data retention and deletion: Personal data will only be processed for as long as is necessary to fulfil the processing purposes described above. If this data is no longer required for the stated purposes, it will be deleted. In certain situations, however, the data may be retained for a longer period in order to comply with legal requirements, provided this is necessary and proportionate. In such cases, the data will be deleted as soon as it is no longer required for these purposes.
- Technical and organisational measures: We have implemented the necessary contractual, technical and organisational measures to ensure the security of all data processed by us. This data is processed exclusively for the specified purposes. Incoming reports are handled by authorised persons who are granted access to the respective reports and carry out the subsequent review of the facts. Our employees are specially trained, instructed and bound to maintain the strictest confidentiality in the proper conduct of factual reviews.
Whistleblower systems
As part of our whistleblowing procedure, we use external providers. In doing so, we act in accordance with statutory requirements and ensure that the technical and organisational security measures we observe are also met by the external providers.
- Processed data types: Master data (e.g. full name, residential address, contact information, customer number, etc.); employee data (information on employees and other persons in an employment relationship); contact data (e.g. postal and email addresses or telephone numbers); content data (e.g. textual or visual messages and posts as well as information relating to them, such as details on authorship or time of creation). Usage data (e.g. page views and dwell time, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions).
- Affected persons Employees (e.g. staff, applicants, temporary workers and other personnel); third parties; whistleblowers; users (e.g. website visitors, users of online services); business and contractual partners.
- Purposes of processing and legitimate interests: Whistleblower protection. Security measures.
- Storage and deletion: Erasure in accordance with the details in the section „General Information on Data Storage and Erasure“.
- Legal basis: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR); Legal obligation (Art. 6 para. 1 sentence 1 lit. c) GDPR). Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
Further information on processing operations, procedures and services:
- LegalTegrity Whistleblowing channel and reporting system; Service provider: LegalTegrity GmbH, Platz der Einheit 2, 60327 Frankfurt, Germany; Legal basis: Legal obligation (Art. 6(1)(c) GDPR); Website https://legaltegrity.com/; Privacy policy: https://legaltegrity.com/datenschutz/. Data Processing Agreement: Provided by the service provider.
Modification and update
We kindly ask you to check the content of our privacy policy on a regular basis. We will amend the privacy policy as soon as changes to the data processing carried out by us make this necessary. We will inform you as soon as the changes require any action on your part (e.g. consent) or any other individual notification.
Where we state addresses and contact details of companies and organisations in this privacy policy, please note that these addresses may change over time and we kindly ask you to check the details before making contact.
Definitions of terms
In this section, you will find an overview of the terminology used in this privacy policy. Where terms are defined by law, their statutory definitions shall apply. The explanations below, on the other hand, are primarily intended to aid understanding.
- Employees: Employees are defined as individuals who are in an employment relationship, whether as staff, salaried employees or in similar positions. An employment relationship is a legal relationship between an employer and an employee that is established by an employment contract or agreement. It involves the employer's obligation to pay remuneration to the employee while the employee provides their work performance. The employment relationship comprises various phases, including the commencement, in which the employment contract is concluded, the execution, in which the employee carries out their work activity, and the termination, when the employment relationship ends, whether through dismissal, termination agreement or otherwise. Employee data is all information relating to these individuals that is in the context of their employment. This includes aspects such as personal identification data, identification numbers, salary and bank details, working hours, holiday entitlements, health data and performance appraisals.
- Master data: Master data includes essential information necessary for the identification and management of contractual partners, user accounts, profiles and similar associations. This data may include, amongst other things, personal and demographic details such as names, contact information (addresses, telephone numbers, email addresses), dates of birth and specific identifiers (user IDs). Master data forms the basis for any formal interaction between individuals and services, institutions or systems by enabling unambiguous association and communication.
- Content data: Content data comprises information generated during the creation, editing and publication of content of all kinds. This category of data can include texts, images, videos, audio files and other multimedia content published on various platforms and media. Content data is not limited to the actual content itself, but also includes metadata that provides information about the content itself, such as tags, descriptions, author information and publication dates.
- Click tracking: Clicktracking allows you to monitor user movements across an entire online offering. As the results of these tests are more accurate when user interaction can be tracked over a certain period of time (e.g. to help us find out whether a user likes to return), cookies are generally stored on the users' computers for these testing purposes.
- Contact details: Contact details are essential information that enable communication with individuals or organisations. They include phone numbers, postal addresses and email addresses, amongst other things, as well as means of communication such as social media handles and instant messaging identifiers.
- Conversion measurement Conversion measurement (also referred to as „visitor action evaluation“) is a procedure that makes it possible to determine the effectiveness of marketing measures. For this purpose, a cookie is generally stored on users' devices within the websites where the marketing measures take place and is then retrieved again on the target website. For example, this enables us to trace whether the advertisements placed by us on other websites were successful.
- Artificial Intelligence (AI): The purpose of data processing by Artificial Intelligence (AI) includes the automated analysis and processing of user data in order to recognise patterns, make predictions, and improve the efficiency and quality of our services. This involves the collection, cleaning and structuring of data, the training and application of AI models, and the continuous review and optimisation of results, and is carried out exclusively with the consent of the users or on the basis of legal permissions.
- Performance and behaviour data: Performance and behavioural data relate to information associated with how individuals perform tasks or behave in a specific context, such as in an educational, work or social environment. This data can include metrics such as productivity, efficiency, work quality, attendance and adherence to policies or procedures. Behavioural data could include interactions with colleagues, communication styles, decision-making processes and reactions to various situations. These types of data are often used for performance reviews, training and development measures, and decision-making within organisations.
- Meta data, communication data and procedural data: Meta data, communication data and procedural data are categories containing information about the way in which data is processed, transmitted and managed. Meta data, also known as data about data, comprises information that describes the context, origin and structure of other data. It can include details on the file size, creation date, author of a document and change histories. Communication data records the exchange of information between users via various channels, such as email traffic, call logs, social media messages and chat histories, including the people involved, timestamps and transmission routes. Procedural data describes the processes and workflows within systems or organisations, including workflow documentation, transaction and activity logs, as well as audit logs used for tracking and verifying operations.
- Usage data: Usage data refers to information that captures how users interact with digital products, services or platforms. This data encompasses a wide range of information that shows how users use applications, which features they prefer, how long they stay on certain pages and the paths they take to navigate through an application. Usage data can also include frequency of use, activity timestamps, IP addresses, device information and location data. It is particularly valuable for analysing user behaviour, optimising user experiences, personalising content and improving products or services. Furthermore, usage data plays a crucial role in identifying trends, preferences and potential problem areas within digital offerings.
- Personal data: „Personal data means any information relating to an identified or identifiable natural person (hereinafter referred to as data subject); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g. cookie) or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
- Profiles with user-related information: The processing of „profiles with user-related information“, or „profiles“ for short, comprises any type of automated processing of personal data which consists in using this personal data to analyse, evaluate or predict certain personal aspects relating to a natural person (depending on the type of profiling, this may include various information regarding demographics, behaviour and interests, such as interaction with websites and their content, etc.) (e.g. interests in certain content or products, clicking behaviour on a website or location). Cookies and web beacons are frequently used for profiling purposes.
- Log data: Log data is information about events or activities that have been logged in a system or network. This data typically contains information such as timestamps, IP addresses, user actions, error messages, and other details about the use or operation of a system. Log data is often used for analysing system problems, for security monitoring, or for generating performance reports.
- Reach measurement Audience measurement (also referred to as web analytics) serves to evaluate visitor traffic to an online service and can encompass the behaviour or interests of visitors regarding specific information, such as website content. With the help of audience analysis, operators of online services can, for example, identify what time users visit their websites and which content they are interested in. As a result, they can, for example, better adapt the content of the websites to the needs of their visitors. For the purposes of audience analysis, pseudonymous cookies and web beacons are frequently used in order to recognise returning visitors and thus obtain more precise analyses regarding the usage of an online service.
- Remarketing Remarketing or retargeting refers to the practice of noting which products a user has shown an interest in on a website, for advertising purposes for example, in order to remind the user of these products on other websites, such as in advertisements.
- Tracking: Tracking is when the behaviour of users can be tracked across multiple online services. As a rule, behavioural and interest-related information regarding the online services used is stored in cookies or on the servers of the providers of the tracking technologies (known as profiling). This information can subsequently be used, for example, to display advertisements to users that are likely to match their interests.
- Person in charge The „controller“ means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
- Processing: „Processing means any operation or set of operations which is performed on personal data, whether or not by automated means. The term is broad and covers practically any handling of data, be it collection, analysis, storage, transmission or erasure.
- Contract details: Contract data are specific information relating to the formalisation of an agreement between two or more parties. They document the terms and conditions under which services or products are provided, exchanged or sold. This data category is essential for the administration and fulfilment of contractual obligations and includes both the identification of the contracting parties and the specific terms and conditions of the agreement. Contract data may include start and end dates of the contract, the nature of the agreed services or products, pricing agreements, payment terms, termination rights, renewal options and special conditions or clauses. They serve as the legal basis for the relationship between the parties and are crucial for clarifying rights and obligations, enforcing claims and resolving disputes.
- Payment details: Payment data comprises all information required to process payment transactions between buyers and sellers. This data is of crucial importance for electronic commerce, online banking and any other form of financial transaction. It includes details such as credit card numbers, bank details, payment amounts, transaction dates, verification numbers and billing information. Payment data may also include information on payment status, chargebacks, authorisations and fees.
- Target group formation Audience creation (known in English as „custom audiences“) refers to the process of defining target groups for advertising purposes, such as the display of advertisements. For example, a user's interest in specific products or topics on the internet can be used to infer that this user might be interested in advertisements for similar products or the online shop where they viewed those products. „Lookalike Audiences“ (or similar audiences), on the other hand, refers to when content deemed suitable is displayed to users whose profiles or interests presumably match those of the users for whom the profiles were created. Cookies and web beacons are routinely used for the purposes of creating custom audiences and lookalike audiences.
