Data protection
Note on the responsible body
The controller responsible for data processing on this website is
KUMM-Technik GmbH
Am Willrother Berg 2
56594 Willroth
Germany
Phone: +49 2687-9259200
E-mail: info@kumm-technik.de
The controller is the natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data (e.g. names, e-mail addresses, etc.).
Privacy Policy
Preamble
With this Privacy Policy, we would like to inform you about the types of personal data (hereinafter also referred to simply as “data”) that we process, the purposes for which we process them and the extent of such processing. This Privacy Policy applies to all processing of personal data carried out by us, both in connection with the provision of our services and, in particular, on our websites, in mobile applications and within external online presences, such as our social media profiles (hereinafter collectively referred to as the “Online Offering”).
The terms used are gender-neutral.
Last updated: 11 June 2026
Table of Contents
- Preamble
- Controller
- Overview of Processing Activities
- Relevant Legal Bases
- Security Measures
- Disclosure of Personal Data
- International Data Transfers
- General Information on Data Retention and Deletion
- Rights of Data Subjects
- Business Services
- Business Processes and Procedures
- Providers and Services Used in the Course of Business Activities
- Provision of the Online Offering and Web Hosting
- Use of Cookies
- Contact and Enquiry Management
- Communication via Messenger Services
- Web Analytics, Monitoring and Optimisation
- Online Marketing
- Social Media Presences
- Plug-ins, Embedded Functions and Content
- Application Procedures
- Definitions
Controller
KUMM-Technik GmbH
Am Willrother Berg 2
56594 Willroth
Germany
Email address: kontakt@kumm-technik.de
Legal notice: https://kumm-technik.de/impressum/
Overview of Processing Activities
The following overview summarises the types of data processed, the purposes for which they are processed and the categories of data subjects concerned.
Types of Data Processed
- Master data.
- Payment data.
- Contact data.
- Content data.
- Contract data.
- Usage data.
- Meta, communication and procedural data.
- Applicant data.
- Event data (Facebook).
- Log data.
Categories of Data Subjects
- Recipients of services and clients.
- Prospective customers.
- Communication partners.
- Users.
- Applicants.
- Participants in prize draws and competitions.
- Business and contractual partners.
- Third parties.
Purposes of Processing
- Provision of contractual services and fulfilment of contractual obligations.
- Communication.
- Security measures.
- Direct marketing.
- Reach measurement.
- Tracking.
- Office and organisational procedures.
- Remarketing.
- Conversion measurement.
- Click tracking.
- Audience building.
- Organisational and administrative procedures.
- Application procedures.
- Conducting prize draws and competitions.
- Feedback.
- Marketing.
- Profiles containing user-related information.
- Provision of our Online Offering and user-friendliness.
- Information technology infrastructure.
- Financial and payment management.
- Public relations.
- Sales promotion.
- Business processes and commercial procedures.
Relevant Legal Bases
Relevant legal bases under the GDPR
Below you will find an overview of the legal bases under the GDPR on which we process personal data. Please note that, in addition to the provisions of the GDPR, national data protection provisions may apply in your or our country of residence or establishment. If more specific legal bases are relevant in individual cases, we will inform you of these in this Privacy Policy.
- Consent (Art. 6(1), first sentence, point (a) GDPR) – The data subject has given consent to the processing of personal data concerning them for one or more specific purposes.
- Performance of a contract and pre-contractual enquiries (Art. 6(1), first sentence, point (b) GDPR) – Processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.
- Legal obligation (Art. 6(1), first sentence, point (c) GDPR) – Processing is necessary for compliance with a legal obligation to which the controller is subject.
- Legitimate interests (Art. 6(1), first sentence, point (f) GDPR) – Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests, fundamental rights and freedoms of the data subject which require protection of personal data.
- Processing in the context of an application procedure (Section 26(1), first sentence, BDSG): We process applicants’ personal data where this is necessary for deciding whether to establish an employment relationship. Where processing is exceptionally based on voluntary consent, it is carried out on the basis of Section 26(2) BDSG in conjunction with Art. 6(1), first sentence, point (a) GDPR.
Where special categories of personal data within the meaning of Art. 9(1) GDPR are processed in the context of an application procedure, this is done subject to the conditions of Section 26(3) BDSG in conjunction with Art. 9(2), point (b) GDPR. Where processing is based on explicit and voluntary consent, it is based on Section 26(2) BDSG in conjunction with Art. 9(2), point (a) GDPR.
National data protection regulations in Germany
In addition to the data protection provisions of the GDPR, national data protection regulations apply in Germany. This includes, in particular, the Federal Data Protection Act (Bundesdatenschutzgesetz – BDSG). The BDSG contains, among other things, specific provisions concerning the right of access, the right to erasure, the right to object, the processing of special categories of personal data, processing for other purposes and transfers, as well as automated decision-making in individual cases, including profiling. In addition, the data protection laws of the individual German federal states may apply.
Relevant legal bases under the Swiss Data Protection Act
If you are located in Switzerland, we process your data on the basis of the Swiss Federal Act on Data Protection (the “Swiss DPA”). Unlike the GDPR, for example, the Swiss DPA generally does not require that a specific legal basis for the processing of personal data be stated. Personal data must nevertheless be processed lawfully, in good faith and proportionately (Art. 6(1) and (2) Swiss DPA). In addition, we collect personal data only for a specific purpose that is recognisable to the data subject and process it only in a manner compatible with that purpose (Art. 6(3) Swiss DPA).
Note on the applicability of the GDPR and the Swiss DPA
This Privacy Policy is intended to provide information both under the Swiss DPA and under the General Data Protection Regulation (GDPR). For reasons of broader geographical applicability and comprehensibility, we therefore use the terminology of the GDPR. In particular, instead of the Swiss DPA terms corresponding to “processing” of “personal data”, “overriding interest” and “sensitive personal data”, we use the GDPR terminology “processing” of “personal data”, “legitimate interest” and “special categories of data”. However, where the Swiss DPA applies, the legal meaning of the terms continues to be determined in accordance with the Swiss DPA.
Security Measures
In accordance with legal requirements and taking into account the state of the art, implementation costs, the nature, scope, circumstances and purposes of processing, as well as the varying likelihood and severity of risks to the rights and freedoms of natural persons, we implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk.
These measures include, in particular, safeguarding the confidentiality, integrity and availability of data by controlling physical and electronic access to data, as well as access to, input of, disclosure of, availability of and separation of such data. In addition, we have established procedures to enable the exercise of data subject rights, the deletion of data and responses to risks affecting the data. We also take the protection of personal data into account when developing or selecting hardware, software and procedures, in accordance with the principles of data protection by design and data protection by default.
Securing online connections using TLS/SSL encryption technology (HTTPS)
To protect user data transmitted via our online services from unauthorised access, we use TLS/SSL encryption technology. Secure Sockets Layer (SSL) and Transport Layer Security (TLS) are cornerstones of secure data transmission on the internet. These technologies encrypt information transmitted between a website or app and the user’s browser (or between two servers), thereby protecting the data against unauthorised access. TLS, as the more advanced and secure version of SSL, ensures that all data transmissions meet high security standards. Where a website is secured by an SSL/TLS certificate, this is indicated by HTTPS in the URL. This provides users with an indication that their data is transmitted securely and in encrypted form.
Disclosure of Personal Data
In the course of processing personal data, such data may be transmitted to or disclosed to other bodies, companies, legally independent organisational units or persons. Recipients may include, for example, service providers commissioned with IT tasks or providers of services and content integrated into a website. In such cases, we comply with the applicable legal requirements and, in particular, enter into appropriate contracts or agreements with recipients where required to protect your data.
Forwarding enquiries to sales, dealer and service partners
If, based on the content of your enquiry, the requested product or regional responsibility, your enquiry is to be handled by one of our legally independent dealers, importers, sales or service partners, we transmit the personal data required for this purpose to the relevant partner.
The data transmitted may include, in particular: name, company, address or postal code, email address, telephone number, and the content and subject matter of your enquiry.
The transfer takes place for the purpose of handling your enquiry, providing professional advice, contacting you, preparing an offer and, where applicable, carrying out pre-contractual measures.
The legal basis is Art. 6(1), point (b) GDPR where the disclosure is necessary to handle an enquiry initiated by you or to carry out pre-contractual measures. Where the disclosure is not necessary to handle your enquiry, it is made only on the basis of your consent in accordance with Art. 6(1), point (a) GDPR.
The respective dealers, importers, sales or service partners process the data transmitted to them as independent controllers in accordance with their own privacy information. Data is transferred only to the extent required to handle the enquiry.
The data is deleted as soon as it is no longer required for the stated purposes and no statutory retention or documentation obligations prevent deletion.
International Data Transfers
Data processing in third countries
Where we transfer data to a third country, i.e. a country outside the European Union (EU) or the European Economic Area (EEA), or where this occurs in connection with the use of third-party services or the disclosure or transfer of data to other persons, bodies or companies (which can be identified by the postal address of the relevant provider or where this Privacy Policy expressly refers to transfers to third countries), this is always carried out in accordance with the applicable legal requirements.
For transfers of personal data to countries outside the European Union and the European Economic Area, we comply with the requirements of Art. 44 et seq. GDPR.
Where the European Commission has adopted an adequacy decision for a third country, data may be transferred on that basis. For transfers to recipients in the United States, the EU-US Data Privacy Framework may in particular serve as a basis where the specific recipient is appropriately certified.
Where no adequacy decision applies, data transfers may be based on appropriate safeguards, in particular the Standard Contractual Clauses approved by the European Commission. Further information on the relevant recipients and transfer mechanisms can be found in the sections relating to the individual services used. For each service provider, we indicate whether it is certified under the DPF and whether Standard Contractual Clauses are in place. Further information on the DPF and a list of certified organisations can be found on the website of the U.S. Department of Commerce at https://www.dataprivacyframework.gov/ (in English).
For transfers to other third countries, corresponding safeguards apply, including in particular Standard Contractual Clauses, explicit consent or transfers required by law. Information on third-country transfers and applicable adequacy decisions is available from the European Commission at: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection_en?prefLang=en.
Disclosure of personal data abroad under Swiss law
Under the Swiss DPA, we disclose personal data abroad only where adequate protection of the data subjects is ensured (Art. 16 Swiss DPA). Where the Swiss Federal Council has not determined that adequate protection exists (list: https://www.bj.admin.ch/bj/en/home/state/data-protection/international/recognition-states.html), we implement alternative safeguards.
For data transfers to the United States, we rely primarily on the Data Privacy Framework (DPF), which Switzerland recognised as an adequate framework by adequacy decision dated 15 September 2024. In addition, we have entered into standard data protection clauses with the relevant providers, approved by the Federal Data Protection and Information Commissioner (FDPIC), which establish contractual obligations to protect your data.
This dual safeguard provides comprehensive protection for your data: the DPF forms the primary level of protection, while the standard data protection clauses provide an additional layer of protection. If the DPF framework changes, the standard data protection clauses serve as a reliable fallback mechanism. This helps ensure that your data continues to receive an appropriate level of protection even in the event of political or legal changes.
For each service provider, we indicate whether it is certified under the DPF and whether standard data protection clauses are in place. The list of certified organisations and further information on the DPF can be found on the U.S. Department of Commerce website at https://www.dataprivacyframework.gov/ (in English).
For data transfers to other third countries, corresponding safeguards apply, including international treaties, specific guarantees, standard data protection clauses approved by the FDPIC, or binding corporate rules previously recognised by the FDPIC or another competent data protection authority.
General Information on Data Retention and Deletion
We delete personal data processed by us in accordance with statutory provisions once the underlying consent has been withdrawn or there is no longer another legal basis for processing. This applies where the original purpose of the processing no longer applies or the data is no longer required. Exceptions apply where statutory obligations or specific interests require longer retention or archiving.
In particular, data that must be retained for commercial or tax-law reasons, or whose retention is necessary for the establishment, exercise or defence of legal claims or the protection of the rights of other natural or legal persons, must be archived accordingly.
Our privacy information contains additional information concerning the retention and deletion of data that applies specifically to particular processing operations.
Where several retention periods or deletion deadlines apply to the same data, the longest period is decisive. Data that is no longer required for its originally intended purpose but is retained due to statutory requirements or other reasons is processed exclusively for the purposes that justify its retention.
Retention and deletion of data under German law
The following general periods apply to retention and archiving under German law:
- 10 years – Retention period for books and records, annual financial statements, inventories, management reports, opening balance sheets and the operating instructions and other organisational documents required for understanding them (Section 147(1) no. 1 in conjunction with subsection (3) AO, Section 14b(1) UStG, Section 257(1) no. 1 in conjunction with subsection (4) HGB).
- 8 years – Accounting documents, such as invoices and expense receipts (Section 147(1) nos. 4 and 4a in conjunction with subsection (3), first sentence, AO and Section 257(1) no. 4 in conjunction with subsection (4) HGB).
- 6 years – Other business documents: received commercial or business correspondence, reproductions of sent commercial or business correspondence, and other documents relevant for taxation, such as hourly wage records, operating accounting sheets, calculation documents, price labels, payroll documents where these are not already accounting documents, and cash register receipts (Section 147(1) nos. 2, 3 and 5 in conjunction with subsection (3) AO, Section 257(1) nos. 2 and 3 in conjunction with subsection (4) HGB).
- 3 years – Data required to take account of potential warranty and damages claims or similar contractual claims and rights, and to handle related enquiries, based on previous business experience and common industry practice, are retained for the regular statutory limitation period of three years (Sections 195, 199 BGB).
Retention and deletion of data under Swiss law
The following general periods apply to retention and archiving under Swiss law:
- 10 years – Retention period for books and records, annual financial statements, inventories, management reports, opening balance sheets, accounting documents and invoices, as well as all necessary operating instructions and other organisational documents (Art. 958f Swiss Code of Obligations (CO)).
- 10 years – Data required to take account of potential claims for damages or similar contractual claims and rights, and to handle related enquiries, based on previous business experience and common industry practice, are retained for the statutory limitation period of ten years unless a shorter five-year period applies in specific cases (Arts. 127 and 130 CO). Claims become time-barred after five years in relation to rents, lease payments and capital interest and other periodic payments, deliveries of food, board and lodging debts, work performed by tradespeople, retail sales of goods, medical treatment, professional services provided by lawyers, legal agents, authorised representatives and notaries, and claims arising from employment relationships (Art. 128 CO).
Commencement of periods at the end of the year
Where a period does not expressly begin on a specific date and is at least one year in length, it begins automatically at the end of the calendar year in which the triggering event occurred. In the case of ongoing contractual relationships under which data is stored, the triggering event is the date on which termination or another form of ending the legal relationship takes effect.
Rights of Data Subjects
Rights of data subjects under the GDPR
As a data subject, you have various rights under the GDPR, arising in particular from Arts. 15 to 21 GDPR:
- Right to object: You have the right, on grounds relating to your particular situation, to object at any time to the processing of personal data concerning you which is based on Art. 6(1), point (e) or (f) GDPR; this also applies to profiling based on those provisions. Where personal data concerning you is processed for direct marketing purposes, you have the right to object at any time to the processing of personal data concerning you for such marketing; this also applies to profiling to the extent that it is related to such direct marketing.
- Right to withdraw consent: You have the right to withdraw consent you have given at any time.
- Right of access: You have the right to obtain confirmation as to whether data concerning you is being processed and, where that is the case, to obtain access to that data as well as further information and a copy of the data in accordance with statutory requirements.
- Right to rectification: In accordance with statutory requirements, you have the right to request completion of data concerning you or rectification of inaccurate data concerning you.
- Right to erasure and restriction of processing: Subject to statutory requirements, you have the right to request that data concerning you be erased without undue delay or, alternatively, to request restriction of processing.
- Right to data portability: You have the right to receive data concerning you that you have provided to us, in accordance with statutory requirements, in a structured, commonly used and machine-readable format, or to request its transmission to another controller.
- Right to lodge a complaint with a supervisory authority: Without prejudice to any other administrative or judicial remedy, you also have the right, in accordance with statutory requirements, to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your habitual residence, your place of work or the place of the alleged infringement, if you consider that the processing of personal data relating to you infringes the GDPR.
Rights of data subjects under the Swiss DPA
As a data subject, you have the following rights subject to the provisions of the Swiss DPA:
- Right of access: You have the right to obtain confirmation as to whether personal data concerning you is being processed and to receive the information necessary to enable you to exercise your rights under the law and to ensure transparent data processing.
- Right to data disclosure or transfer: You have the right to request the disclosure of personal data that you have provided to us in a commonly used electronic format.
- Right to rectification: You have the right to request the rectification of inaccurate personal data concerning you.
- Right to object, deletion and destruction: You have the right to object to the processing of your data and to request that personal data concerning you be deleted or destroyed.
Business Services
We process personal data of our contractual and business partners, such as customers, clients, prospective customers, suppliers and other cooperation partners (collectively “Contractual Partners”), for the initiation, performance and handling of contractual relationships and comparable legal relationships. This also includes pre-contractual measures taken at the request of the data subject and communication relating to the respective contractual relationship.
Processing serves, in particular, to fulfil our primary and ancillary contractual obligations. This includes providing the agreed services, any updating and information obligations, handling warranty claims and other service disruptions, processing withdrawals, termination of continuing obligations, reversals, refunds and handling other contract-related declarations and enquiries. Both one-off contracts and ongoing contractual relationships are covered.
The data processed includes, in particular, master data such as name, address and, where applicable, company, contact details such as email address and telephone number, contract and service data such as the subject matter of the contract, contract term, order or transaction number, usage and service data, payment and billing data, as well as communication content and histories. Where necessary, we also process data disclosed or transmitted to us in connection with carrying out an order.
In addition, we process data to protect our rights and to comply with statutory obligations. This includes, in particular, retention obligations under commercial and tax law, documentation duties and, where applicable, evidence and accountability obligations. Processing is also carried out on the basis of our legitimate interests in proper business management, internal administration, risk management and IT security, and in protecting our business operations and Contractual Partners against misuse, threats to data, confidential information and other legal interests. This may also include engaging external service providers such as IT and telecommunications providers, transport and logistics companies, payment service providers, banks, tax advisers, legal advisers or other agents where necessary for contract performance or compliance with legal obligations.
Personal data is disclosed to third parties only where this is necessary for contract performance, pre-contractual measures, the pursuit of legitimate interests or compliance with legal obligations. We provide separate information in this Privacy Policy concerning any further processing, in particular for marketing purposes.
We inform Contractual Partners which data is required in each individual case when collecting the data, for example by marking required fields in online forms or during personal contact.
Data is deleted as soon as it is no longer required for the aforementioned purposes and no statutory retention obligations prevent deletion. Statutory retention periods, especially under commercial and tax law, may require longer storage. Data transmitted in connection with a specific order is deleted after completion of the order and expiry of any retention periods, provided that no further statutory or contractual obligation to retain it applies.
The legal basis for processing is Art. 6(1), point (b) GDPR for pre-contractual measures and performance of the respective contractual relationship, and Art. 6(1), point (c) GDPR for compliance with legal obligations. Where processing is based on legitimate interests, it is carried out pursuant to Art. 6(1), point (f) GDPR. Where Art. 6(1), point (f) GDPR is relied upon, this serves our legitimate interests in proper and efficient business organisation, internal administration and documentation of business transactions, the establishment, exercise and defence of legal claims, ensuring IT and data security, preventing misuse and fraud, and the economic management and further development of our business operations. These interests exist, in particular, in ensuring secure and legally compliant business operations and safeguarding our entrepreneurial ability to act.
- Types of data processed: Master data (e.g. full name, residential address, contact information, customer number, etc.); payment data (e.g. bank details, invoices, payment history); contact data (e.g. postal and email addresses or telephone numbers); contract data (e.g. subject matter of contract, term, customer category).
- Data subjects: Recipients of services and clients; prospective customers; business and contractual partners.
- Purposes of processing and legitimate interests: Provision of contractual services and fulfilment of contractual obligations; communication; office and organisational procedures; organisational and administrative procedures; business processes and commercial procedures.
- Retention and deletion: Deletion in accordance with the information in the section “General Information on Data Retention and Deletion”.
- Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6(1), first sentence, point (b) GDPR); legal obligation (Art. 6(1), first sentence, point (c) GDPR); legitimate interests (Art. 6(1), first sentence, point (f) GDPR).
Further information on processing operations, procedures and services
- Automotive industry and vehicle technology: We process data relating to our customers and clients in order to provide them with the development, production and supply of vehicles and vehicle technologies and related services. The required information includes information needed to implement and bill projects, as well as contact information required for necessary coordination. Where we obtain access to information concerning end customers, employees or other persons, we process such data in accordance with statutory and contractual requirements; legal bases: performance of a contract and pre-contractual enquiries (Art. 6(1), first sentence, point (b) GDPR), legal obligation (Art. 6(1), first sentence, point (c) GDPR), legitimate interests (Art. 6(1), first sentence, point (f) GDPR).
Business Processes and Procedures
Personal data relating to recipients of services and clients – including customers, clients or, in specific cases, principals, patients or business partners, as well as other third parties – is processed in connection with contractual and comparable legal relationships and pre-contractual measures such as the initiation of business relationships. This processing supports and facilitates commercial processes in areas such as customer management, sales, payment transactions, accounting and project management.
The data collected serves to fulfil contractual obligations and to organise business processes efficiently. This includes processing business transactions, managing customer relationships, optimising sales strategies and ensuring internal accounting and financial processes. In addition, the data supports the protection of the controller’s rights and facilitates administrative tasks and company organisation.
Personal data may be disclosed to third parties where this is necessary to fulfil the aforementioned purposes or statutory obligations. After statutory retention periods have expired or once the purpose of processing no longer applies, the data is deleted. This also includes data that must be stored for longer periods due to tax-law and statutory documentation obligations.
- Types of data processed: Master data (e.g. full name, residential address, contact information, customer number, etc.); payment data (e.g. bank details, invoices, payment history); contact data (e.g. postal and email addresses or telephone numbers); content data (e.g. text or image-based messages and posts and related information such as authorship or time of creation); contract data (e.g. subject matter of contract, term, customer category); log data (e.g. log files relating to logins, retrieval of data or access times); usage data (e.g. page views and time spent, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions); meta, communication and procedural data (e.g. IP addresses, time information, identification numbers, persons involved).
- Data subjects: Recipients of services and clients; prospective customers; communication partners; business and contractual partners; third parties; users (e.g. website visitors, users of online services).
- Purposes of processing and legitimate interests: Provision of contractual services and fulfilment of contractual obligations; office and organisational procedures; business processes and commercial procedures; communication; marketing; sales promotion; public relations; financial and payment management; information technology infrastructure (operation and provision of information systems and technical equipment such as computers, servers, etc.).
- Retention and deletion: Deletion in accordance with the information in the section “General Information on Data Retention and Deletion”.
- Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6(1), first sentence, point (b) GDPR); legitimate interests (Art. 6(1), first sentence, point (f) GDPR); legal obligation (Art. 6(1), first sentence, point (c) GDPR).
Further information on processing operations, procedures and services
- Contact management and contact maintenance: Procedures required for the organisation, maintenance and safeguarding of contact information (e.g. establishment and maintenance of a central contact database, regular updating of contact information, monitoring data integrity, implementation of data protection measures, ensuring access controls, performing backups and restoring contact data, training employees in the effective use of contact management software, regular review of communication history and adaptation of contact strategies); legal bases: performance of a contract and pre-contractual enquiries (Art. 6(1), first sentence, point (b) GDPR), legitimate interests (Art. 6(1), first sentence, point (f) GDPR).
- General payment transactions: Procedures required for carrying out payment transactions, monitoring bank accounts and controlling payment flows (e.g. preparing and checking transfers, processing direct debits, checking bank statements, monitoring incoming and outgoing payments, managing returned direct debits, account reconciliation, cash management); legal bases: performance of a contract and pre-contractual enquiries (Art. 6(1), first sentence, point (b) GDPR), legitimate interests (Art. 6(1), first sentence, point (f) GDPR).
- Accounting, accounts payable and accounts receivable: Procedures required to record, process and control business transactions in accounts payable and accounts receivable (e.g. preparing and reviewing incoming and outgoing invoices, monitoring and managing outstanding items, carrying out payment transactions, dunning procedures, reconciling receivables and liabilities, accounts payable and accounts receivable); legal bases: performance of a contract and pre-contractual enquiries (Art. 6(1), first sentence, point (b) GDPR), legal obligation (Art. 6(1), first sentence, point (c) GDPR), legitimate interests (Art. 6(1), first sentence, point (f) GDPR).
- Financial accounting and taxes: Procedures required to record, manage and control financially relevant business transactions and to calculate, report and pay taxes (e.g. account assignment and posting of business transactions, preparation of quarterly and annual financial statements, payment transactions, dunning procedures, account reconciliation, tax advice, preparation and submission of tax returns, tax administration); legal bases: performance of a contract and pre-contractual enquiries (Art. 6(1), first sentence, point (b) GDPR), legal obligation (Art. 6(1), first sentence, point (c) GDPR), legitimate interests (Art. 6(1), first sentence, point (f) GDPR).
- Marketing, advertising and sales promotion: Procedures required in connection with marketing, advertising and sales promotion (e.g. market analysis and audience definition, development of marketing strategies, planning and execution of advertising campaigns, design and production of advertising materials, online marketing including SEO and social media campaigns, event marketing and trade fair participation, customer loyalty programmes, sales promotion measures, performance measurement and optimisation of marketing activities, budget management and cost control); legal basis: legitimate interests (Art. 6(1), first sentence, point (f) GDPR).
- Public relations: Procedures required in connection with public relations and PR activities (e.g. development and implementation of communication strategies, planning and execution of PR campaigns, preparation and distribution of press releases, maintaining media contacts, monitoring and analysing media coverage, organising press conferences and public events, crisis communication, creating content for social media and company websites, corporate branding management); legal basis: legitimate interests (Art. 6(1), first sentence, point (f) GDPR).
Providers and Services Used in the Course of Business Activities
In the course of our business activities, we use additional services, platforms, interfaces or plug-ins from third-party providers (collectively, “Services”) in compliance with statutory requirements. Their use is based on our interests in the proper, lawful and economically efficient management of our business operations and internal organisation.
- Types of data processed: Master data (e.g. full name, residential address, contact information, customer number, etc.); payment data (e.g. bank details, invoices, payment history); contact data (e.g. postal and email addresses or telephone numbers); content data (e.g. text or image-based messages and posts and related information such as authorship or time of creation); contract data (e.g. subject matter of contract, term, customer category); usage data (e.g. page views and time spent, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions); meta, communication and procedural data (e.g. IP addresses, time information, identification numbers, persons involved); event data (Facebook) (“Event Data” means information sent to Meta, for example via the Meta Pixel, apps or other channels, relating to individuals or their actions. This may include details of website visits, interactions with content and functions, app installations and product purchases. Event Data is processed for the purpose of creating audiences for content and advertising messages (Custom Audiences). Event Data does not include actual content such as comments, login information or contact information such as names, email addresses or telephone numbers. Meta deletes Event Data after a maximum of two years, and audiences created from such data cease to exist when our Meta user accounts are deleted.).
- Data subjects: Recipients of services and clients; prospective customers; business and contractual partners; users (e.g. website visitors, users of online services); communication partners; third parties.
- Purposes of processing and legitimate interests: Provision of contractual services and fulfilment of contractual obligations; office and organisational procedures; business processes and commercial procedures; provision of our Online Offering and user-friendliness; information technology infrastructure (operation and provision of information systems and technical equipment such as computers, servers, etc.); reach measurement (e.g. access statistics, recognition of returning visitors); tracking (e.g. interest- or behaviour-based profiling, use of cookies); conversion measurement (measuring the effectiveness of marketing measures); audience building; marketing; profiles containing user-related information (creating user profiles); communication; direct marketing (e.g. by email or post); click tracking; organisational and administrative procedures.
- Retention and deletion: Deletion in accordance with the information in the section “General Information on Data Retention and Deletion”.
- Legal bases: Legitimate interests (Art. 6(1), first sentence, point (f) GDPR); performance of a contract and pre-contractual enquiries (Art. 6(1), first sentence, point (b) GDPR); consent (Art. 6(1), first sentence, point (a) GDPR).
Further information on processing operations, procedures and services
- HubSpot CRM: Management of customer contacts, tracking of sales activities, automation of marketing campaigns, analysis of sales data, creation and management of email campaigns, integration with other tools and platforms, management of customer support enquiries, AI-assisted content generation, personalised email creation, predictive sales forecasting, automated workflow descriptions and AI chatbots for customer interaction; service provider: HubSpot Ireland Limited, Ground Floor, Two Dockland Central, Guild Street, Dublin 1, Ireland; legal bases: performance of a contract and pre-contractual enquiries (Art. 6(1), first sentence, point (b) GDPR), legitimate interests (Art. 6(1), first sentence, point (f) GDPR); website: https://www.hubspot.com/products/crm; privacy policy: https://legal.hubspot.com/privacy-policy; data processing agreement: https://legal.hubspot.com/dpa; basis for third-country transfers: EU/EEA – Data Privacy Framework (DPF), Standard Contractual Clauses (https://legal.hubspot.com/dpa); Switzerland – Data Privacy Framework (DPF), Standard Contractual Clauses (https://legal.hubspot.com/dpa).
- Meta Pixel and audience building (Custom Audiences): With the help of the Meta Pixel (or comparable functions for transmitting Event Data or contact information via interfaces in apps), Meta can, among other things, identify visitors to our Online Offering as an audience for the display of advertisements (“Meta Ads”). We therefore use the Meta Pixel to display the Meta Ads placed by us only to users on Meta platforms and within services of partners cooperating with Meta (the “Audience Network”, https://www.facebook.com/audiencenetwork/) who have shown an interest in our Online Offering or who have certain characteristics (e.g. an interest in particular topics or products inferred from websites visited) that we transmit to Meta (“Custom Audiences”). We also use the Meta Pixel to help ensure that our Meta Ads correspond to users’ potential interests and are not perceived as intrusive. In addition, the Meta Pixel enables us to measure the effectiveness of Meta Ads for statistical and market research purposes by determining whether users were redirected to our website after clicking on a Meta Ad (“conversion measurement”); service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; legal basis: consent (Art. 6(1), first sentence, point (a) GDPR); website: https://www.facebook.com; privacy policy: https://www.facebook.com/privacy/policy/; data processing agreement: https://www.facebook.com/legal/terms/dataprocessing; basis for third-country transfers: EU/EEA – Data Privacy Framework (DPF), Standard Contractual Clauses (https://www.facebook.com/legal/EU_data_transfer_addendum); Switzerland – Data Privacy Framework (DPF), Standard Contractual Clauses (https://www.facebook.com/legal/EU_data_transfer_addendum); further information: Users’ Event Data, i.e. information concerning behaviour and interests, is processed for targeted advertising and audience building on the basis of the agreement on joint controllership (“Controller Addendum”, https://www.facebook.com/legal/controller_addendum). Joint controllership is limited to the collection and transmission of data to Meta Platforms Ireland Limited, an EU-based company. Further processing is the sole responsibility of Meta Platforms Ireland Limited, including in particular any transfer of data to its parent company Meta Platforms, Inc. in the United States (on the basis of Standard Contractual Clauses entered into between Meta Platforms Ireland Limited and Meta Platforms, Inc.).
- HubSpot WordPress: Collection of visitor data, analysis of user behaviour, contact management, creation and management of forms, integration with email marketing tools, and tracking of website visitor interactions; service provider: HubSpot Ireland Limited, Ground Floor, Two Dockland Central, Guild Street, Dublin 1, Ireland; legal basis: legitimate interests (Art. 6(1), first sentence, point (f) GDPR); website: https://wordpress.org/plugins/leadin/; privacy policy: https://legal.hubspot.com/privacy-policy; data processing agreement: https://legal.hubspot.com/dpa; basis for third-country transfers: EU/EEA – Data Privacy Framework (DPF), Standard Contractual Clauses (https://legal.hubspot.com/dpa); Switzerland – Data Privacy Framework (DPF), Standard Contractual Clauses (https://legal.hubspot.com/dpa).
- Microsoft 365 Outlook: Use of email and calendar functions for communication and meeting organisation. Contact data (name, email address), content data (messages, attachments, meeting content) and metadata are processed for purposes and interests relating to efficiency and productivity gains, cost efficiency, flexibility, mobility, improved communication and integration with Microsoft 365. Retention of emails and calendar entries is governed by policies defined by administrators or users; by default, there is no automatic deletion. Diagnostic data is also collected for product stability and improvement; service providers: Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland; Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA; legal basis: legitimate interests (Art. 6(1), first sentence, point (f) GDPR); website: https://www.microsoft.com/; privacy policy: https://privacy.microsoft.com/privacystatement; security information: https://www.microsoft.com/trust-center; data processing agreement: https://www.microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA; basis for third-country transfers: EU/EEA – Data Privacy Framework (DPF), Standard Contractual Clauses (Microsoft DPA); Switzerland – Data Privacy Framework (DPF), Standard Contractual Clauses (Microsoft DPA).
Provision of the Online Offering and Web Hosting
We process users’ data in order to make our online services available to them. For this purpose, we process the user’s IP address, which is necessary to transmit the content and functions of our online services to the user’s browser or terminal device.
- Types of data processed: Usage data (e.g. page views and time spent, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions); meta, communication and procedural data (e.g. IP addresses, time information, identification numbers, persons involved); log data (e.g. log files relating to logins, retrieval of data or access times); content data (e.g. text or image-based messages and posts and related information such as authorship or time of creation).
- Data subjects: Users (e.g. website visitors, users of online services).
- Purposes of processing and legitimate interests: Provision of our Online Offering and user-friendliness; information technology infrastructure (operation and provision of information systems and technical equipment such as computers, servers, etc.); security measures.
- Retention and deletion: Deletion in accordance with the information in the section “General Information on Data Retention and Deletion”.
- Legal basis: Legitimate interests (Art. 6(1), first sentence, point (f) GDPR).
Further information on processing operations, procedures and services
- Provision of the Online Offering on rented storage space: To provide our Online Offering, we use storage space, computing capacity and software that we rent or otherwise obtain from a corresponding server provider (also referred to as a “web host”); legal basis: legitimate interests (Art. 6(1), first sentence, point (f) GDPR).
- Collection of access data and log files: Access to our Online Offering is recorded in so-called “server log files”. Server log files may include the address and name of accessed websites and files, date and time of access, transferred data volumes, notification of successful access, browser type and version, the user’s operating system, referrer URL (the previously visited page), and generally IP addresses and the requesting provider. Server log files may be used for security purposes, for example to prevent server overload (in particular in the event of abusive attacks, so-called DDoS attacks), and to ensure server utilisation and stability; legal basis: legitimate interests (Art. 6(1), first sentence, point (f) GDPR). Deletion of data: Log file information is stored for a maximum of 30 days and then deleted or anonymised. Data whose further retention is required for evidentiary purposes is excluded from deletion until the relevant incident has been finally resolved.
- Email transmission and hosting: The web hosting services used by us also include the sending, receiving and storage of emails. For these purposes, the addresses of recipients and senders, as well as additional information relating to email transmission (e.g. participating providers) and the content of the respective emails, are processed. The aforementioned data may also be processed for spam detection. Please note that emails on the internet are generally not sent with end-to-end encryption. Although emails are usually encrypted in transit, they are not encrypted on the sending and receiving servers unless an end-to-end encryption method is used. We therefore cannot accept responsibility for the transmission path of emails between the sender and receipt on our server; legal basis: legitimate interests (Art. 6(1), first sentence, point (f) GDPR).
- Hetzner: Services relating to the provision of information technology infrastructure and associated services (e.g. storage space and/or computing capacity); service provider: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany; legal basis: legitimate interests (Art. 6(1), first sentence, point (f) GDPR); website: https://www.hetzner.com; privacy policy: https://docs.hetzner.com/general/company-and-policy/data-protection-at-hetzner/; data processing agreement: https://docs.hetzner.com/general/company-and-policy/data-protection-at-hetzner/.
- Yoast SEO: Optimisation of websites for search engines; service provider: Yoast B.V., Don Emanuelstraat 3, 6602 GX Wijchen, Netherlands; legal basis: legitimate interests (Art. 6(1), first sentence, point (f) GDPR); website: https://yoast.com/; privacy policy: https://www.newfold.com/privacy-center; further information: Operated within our own hosting environment.
Use of Cookies
The term “cookies” refers to functions that store information on users’ terminal devices and read information from them. Cookies may be used for various purposes, including the functionality, security and convenience of online offerings and the analysis of visitor flows. We use cookies in accordance with statutory requirements. Where required, we obtain users’ consent in advance. Where consent is not required, we rely on our legitimate interests. This applies where storing or reading information is strictly necessary in order to provide content and functions expressly requested by the user. This includes, for example, storing settings and ensuring the functionality and security of our Online Offering. Consent can be withdrawn at any time. We provide clear information about the scope of consent and the cookies used.
Information on legal bases
Where we use cookies or comparable technologies that store information on a user’s terminal device or access information already stored there, this is generally done only on the basis of consent in accordance with Section 25(1) of the German Telecommunications Digital Services Data Protection Act (Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz – TDDDG). Subsequent processing of personal data is carried out on the basis of Art. 6(1), first sentence, point (a) GDPR.
Consent is not required where storing information or accessing information already stored is strictly necessary in order to provide a digital service expressly requested by the user. In such cases, access to the terminal device is based on Section 25(2) no. 2 TDDDG. Subsequent processing of personal data is carried out, depending on the purpose, in particular on the basis of Art. 6(1), first sentence, points (b), (c) or (f) GDPR.
Storage period
With regard to storage periods, the following types of cookies are distinguished:
- Temporary cookies (also session cookies): Temporary cookies are deleted at the latest after a user leaves an Online Offering and closes their terminal device or browser/mobile application.
- Persistent cookies: Persistent cookies remain stored even after the terminal device is closed. For example, login status may be stored and preferred content displayed immediately when the user revisits a website. Likewise, usage data collected via cookies may be used for reach measurement. Unless we provide users with explicit information on the type and storage period of cookies (e.g. when obtaining consent), users should assume that such cookies are persistent and may be stored for up to two years.
General information on withdrawal and objection (opt-out)
Users may withdraw consent they have given at any time and may also object to processing in accordance with statutory requirements, including by using their browser’s privacy settings.
- Types of data processed: Meta, communication and procedural data (e.g. IP addresses, time information, identification numbers, persons involved).
- Data subjects: Users (e.g. website visitors, users of online services).
- Legal bases: Legitimate interests (Art. 6(1), first sentence, point (f) GDPR); consent (Art. 6(1), first sentence, point (a) GDPR).
Further information on processing operations, procedures and services
- Processing cookie data on the basis of consent: We use a consent management solution through which users’ consent is obtained for the use of cookies or for procedures and providers specified within the consent management solution. The procedure serves to obtain, record, manage and enable withdrawal of consent, in particular with respect to cookies and comparable technologies used to store, read and process information on users’ terminal devices. As part of this procedure, users’ consent is obtained for the use of cookies and associated processing operations, including the specific processing operations and providers named in the consent management process. Users can also manage and withdraw their consent. Consent declarations are stored in order to avoid repeated requests and to provide evidence of consent in accordance with legal requirements. Storage takes place server-side and/or in a cookie (an “opt-in cookie”) or by comparable technologies in order to associate consent with a specific user or device. Unless specific information is provided regarding consent management service providers, the following general information applies: consent is stored for up to two years. A pseudonymous user identifier is created and stored together with the time of consent, information concerning the scope of consent (e.g. categories of cookies and/or service providers concerned), as well as information about the browser, system and terminal device used; legal basis: consent (Art. 6(1), first sentence, point (a) GDPR).
- Borlabs Cookie: Storage and management of consent (consent to cookies and data processing), recording of user decisions, display of privacy and cookie notices, enabling users to withdraw or adjust consent; service provider: operated on servers and/or computers under our own data protection responsibility; website: https://borlabs.io/borlabs-cookie/; further information: An individual user ID, language, types of consent and the time at which consent was given are stored server-side and in a cookie on the user’s device.
Contact and Enquiry Management
When you contact us (e.g. by post, contact form, email, telephone or social media), and in the context of existing user and business relationships, the information provided by the enquiring persons is processed to the extent necessary to respond to the contact enquiries and carry out any requested measures.
- Types of data processed: Contact data (e.g. postal and email addresses or telephone numbers); content data (e.g. text or image-based messages and posts and related information such as authorship or time of creation); meta, communication and procedural data (e.g. IP addresses, time information, identification numbers, persons involved); usage data (e.g. page views and time spent, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions).
- Data subjects: Communication partners.
- Purposes of processing and legitimate interests: Communication; organisational and administrative procedures; feedback (e.g. collecting feedback via online forms); provision of our Online Offering and user-friendliness; direct marketing (e.g. by email or post); reach measurement (e.g. access statistics, recognition of returning visitors); conversion measurement (measuring the effectiveness of marketing measures); click tracking; marketing; profiles containing user-related information (creating user profiles).
- Retention and deletion: Deletion in accordance with the information in the section “General Information on Data Retention and Deletion”.
- Legal bases: Legitimate interests (Art. 6(1), first sentence, point (f) GDPR); performance of a contract and pre-contractual enquiries (Art. 6(1), first sentence, point (b) GDPR).
Further information on processing operations, procedures and services
- Contact form: When you contact us via our contact form, by email or through other communication channels, we process the personal data transmitted to us in order to respond to and handle the relevant enquiry. This generally includes information such as name, contact details and, where applicable, other information communicated to us that is required for appropriate handling. We use this data exclusively for the stated purpose of contact and communication; legal bases: performance of a contract and pre-contractual enquiries (Art. 6(1), first sentence, point (b) GDPR), legitimate interests (Art. 6(1), first sentence, point (f) GDPR).
- HubSpot WordPress: Collection of visitor data, analysis of user behaviour, contact management, creation and management of forms, integration with email marketing tools and tracking of website visitor interactions; service provider: HubSpot Ireland Limited, Ground Floor, Two Dockland Central, Guild Street, Dublin 1, Ireland; legal basis: legitimate interests (Art. 6(1), first sentence, point (f) GDPR); website: https://wordpress.org/plugins/leadin/; privacy policy: https://legal.hubspot.com/privacy-policy; data processing agreement: https://legal.hubspot.com/dpa; basis for third-country transfers: EU/EEA – Data Privacy Framework (DPF), Standard Contractual Clauses (https://legal.hubspot.com/dpa); Switzerland – Data Privacy Framework (DPF), Standard Contractual Clauses (https://legal.hubspot.com/dpa).
- HubSpot CRM: Management of customer contacts, tracking of sales activities, automation of marketing campaigns, analysis of sales data, creation and management of email campaigns, integration with other tools and platforms, management of customer support enquiries, AI-assisted content generation, personalised email creation, predictive sales forecasting, automated workflow descriptions and AI chatbots for customer interaction; service provider: HubSpot Ireland Limited, Ground Floor, Two Dockland Central, Guild Street, Dublin 1, Ireland; legal bases: performance of a contract and pre-contractual enquiries (Art. 6(1), first sentence, point (b) GDPR), legitimate interests (Art. 6(1), first sentence, point (f) GDPR); website: https://www.hubspot.com/products/crm; privacy policy: https://legal.hubspot.com/privacy-policy; data processing agreement: https://legal.hubspot.com/dpa; basis for third-country transfers: EU/EEA – Data Privacy Framework (DPF), Standard Contractual Clauses (https://legal.hubspot.com/dpa); Switzerland – Data Privacy Framework (DPF), Standard Contractual Clauses (https://legal.hubspot.com/dpa).
- WhatsApp: A communication service enabling the sending and receiving of text messages, voice messages, images, videos and documents, as well as voice and video calls over the internet. Communication is protected by end-to-end encryption, meaning that content is accessible only to the participating communication partners. To provide the service, the platform processes metadata (e.g. telephone numbers, timestamps and device information) and may use this information to improve functionality, security and service optimisation; service provider: WhatsApp Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; legal basis: legitimate interests (Art. 6(1), first sentence, point (f) GDPR); website: https://www.whatsapp.com/; privacy policy: https://www.whatsapp.com/legal/privacy-policy-eea.
Communication via Messenger Services
We use messenger services for communication purposes and therefore ask you to note the following information concerning how messenger services function, encryption, use of communication metadata and your options to object.
You may also contact us via alternative channels, e.g. telephone or email. Please use the contact options provided to you or those indicated within our Online Offering.
Where content is end-to-end encrypted (i.e. the content of your message and attachments), we point out that the communication content (i.e. the message content and attached images) is encrypted from end to end. This means that the content of messages cannot be viewed, even by the messenger service providers themselves. You should always use a current version of the messenger service with encryption enabled to ensure that message content is encrypted.
However, we also point out to our communication partners that, although messenger service providers cannot access the content, they may be able to determine that and when communication partners communicate with us and may process technical information about the communication partner’s device and, depending on device settings, location information (so-called metadata).
Information on legal bases
Where we ask communication partners for permission before communicating with them via messenger services, the legal basis for our processing of their data is their consent. Otherwise, where we do not request consent and they contact us of their own initiative, for example, we use messenger services in relation to our Contractual Partners and in the context of contract initiation as a contractual measure, and in relation to other prospective customers and communication partners on the basis of our legitimate interests in fast and efficient communication and in meeting the needs of our communication partners regarding communication via messenger services. We also point out that we do not transmit contact details communicated to us to messenger service providers for the first time without your consent.
Withdrawal, objection and deletion
You may withdraw consent at any time and object to communication with us via messenger services at any time. In the case of communication via messenger services, we delete messages in accordance with our general deletion policies (e.g. after the end of contractual relationships, subject to archiving requirements, as described above) and otherwise as soon as we can assume that any enquiries from communication partners have been answered, provided that no reference back to a previous conversation is expected and no statutory retention obligations prevent deletion.
Reservation regarding reference to other communication channels
To ensure your security, please understand that for certain reasons we may not be able to answer enquiries via messenger services. This applies, for example, where contractual details require particularly confidential treatment or a response via messenger service would not satisfy formal requirements. In such cases, we recommend using a more appropriate communication channel.
- Types of data processed: Contact data (e.g. postal and email addresses or telephone numbers); content data (e.g. text or image-based messages and posts and related information such as authorship or time of creation); usage data (e.g. page views and time spent, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions); meta, communication and procedural data (e.g. IP addresses, time information, identification numbers, persons involved).
- Data subjects: Communication partners.
- Purposes of processing and legitimate interests: Communication; direct marketing (e.g. by email or post).
- Retention and deletion: Deletion in accordance with the information in the section “General Information on Data Retention and Deletion”.
- Legal bases: Consent (Art. 6(1), first sentence, point (a) GDPR); performance of a contract and pre-contractual enquiries (Art. 6(1), first sentence, point (b) GDPR); legitimate interests (Art. 6(1), first sentence, point (f) GDPR).
Further information on processing operations, procedures and services
- WhatsApp: A communication service enabling the sending and receiving of text messages, voice messages, images, videos and documents, as well as voice and video calls over the internet. Communication is protected by end-to-end encryption, meaning that content is accessible only to the participating communication partners. To provide the service, the platform processes metadata (e.g. telephone numbers, timestamps and device information) and may use this information to improve functionality, security and service optimisation; service provider: WhatsApp Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; legal basis: legitimate interests (Art. 6(1), first sentence, point (f) GDPR); website: https://www.whatsapp.com/; privacy policy: https://www.whatsapp.com/legal/privacy-policy-eea.
Web Analytics, Monitoring and Optimisation
Web analytics (also referred to as “reach measurement”) is used to evaluate visitor traffic to our Online Offering and may include behaviour, interests or demographic information about visitors, such as age or gender, as pseudonymous values. Reach analysis allows us, for example, to determine when our Online Offering, its functions or content are used most frequently, or which content encourages repeated use. It also enables us to identify areas requiring optimisation.
In addition to web analytics, we may use testing procedures to test and optimise different versions of our Online Offering or its components.
Unless otherwise stated below, profiles, i.e. data combined for a particular usage process, may be created for these purposes and information may be stored in and read from a browser or terminal device. The information collected includes, in particular, websites visited and elements used there, as well as technical information such as the browser used, the computer system used and information on times of use. Where users have consented to the collection of their location data by us or by providers of services used by us, location data may also be processed.
Information on legal bases
Where we ask users for consent to the use of third-party providers, the legal basis for data processing is consent. Otherwise, user data is processed on the basis of our legitimate interests (i.e. our interest in efficient, economical and user-friendly services). In this context, we also refer you to the information concerning the use of cookies in this Privacy Policy.
- Types of data processed: Usage data (e.g. page views and time spent, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions); meta, communication and procedural data (e.g. IP addresses, time information, identification numbers, persons involved).
- Data subjects: Users (e.g. website visitors, users of online services).
- Purposes of processing and legitimate interests: Reach measurement (e.g. access statistics, recognition of returning visitors); profiles containing user-related information (creating user profiles); provision of our Online Offering and user-friendliness.
- Retention and deletion: Deletion in accordance with the information in the section “General Information on Data Retention and Deletion”. Cookies may be stored for up to two years (unless otherwise stated, cookies and comparable storage methods may be stored on users’ devices for a period of two years).
- Security measures: IP masking (pseudonymisation of the IP address).
- Legal bases: Consent (Art. 6(1), first sentence, point (a) GDPR); legitimate interests (Art. 6(1), first sentence, point (f) GDPR).
Further information on processing operations, procedures and services
- Google Analytics: We use Google Analytics to measure and analyse use of our Online Offering on the basis of a pseudonymous user identification number. This identification number does not contain directly identifying data such as names or email addresses. It is used to associate analytical information with a terminal device in order to determine which content users have accessed within one or more usage sessions, which search terms they have used, whether they have accessed content again or interacted with our Online Offering. The time and duration of use, the sources referring users to our Online Offering and technical aspects of their devices and browsers are also stored.Pseudonymous user profiles are created containing information from the use of different devices, and cookies may be used for this purpose. Google Analytics does not log or store individual IP addresses for EU users. Analytics does, however, provide approximate geographical location data by deriving the following metadata from IP addresses: city (and the city’s derived latitude and longitude), continent, country, region, subcontinent and corresponding ID-based equivalents. For EU traffic, IP address data is used solely to derive geolocation data and is then deleted immediately. It is not logged, is not accessible and is not used for any further purposes. Where Google Analytics collects measurement data, all IP lookups for EU traffic take place on EU-based servers before traffic is forwarded to Analytics servers for processing.
The retention period configured by us for event data is two months. The retention period for user data is 14 months. Where a user becomes active again, the retention period for the respective user identifier is reset and begins again. After expiry of the respective retention period, the affected data is automatically deleted as part of Google Analytics’ deletion process. Data retention settings apply to user-level and event-level data. Aggregated data in Google Analytics standard reports is not affected by these retention settings.
Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; legal basis: consent pursuant to Art. 6(1), first sentence, point (a) GDPR in conjunction with Section 25(1) TDDDG; website: https://marketingplatform.google.com/about/analytics/; security measures: IP masking (pseudonymisation of the IP address); privacy policy: https://business.safety.google/privacy/; data processing agreement: https://business.safety.google/adsprocessorterms/; basis for third-country transfers: EU/EEA – Data Privacy Framework (DPF), Standard Contractual Clauses (https://business.safety.google/adsprocessorterms); Switzerland – Data Privacy Framework (DPF), Standard Contractual Clauses (https://business.safety.google/adsprocessorterms); opt-out: browser add-on: https://tools.google.com/dlpage/gaoptout?hl=en; ad personalisation settings: https://myadcenter.google.com/personalizationoff; further information: https://business.safety.google/adsservices/ (types of processing and data processed).
- Google Signals (Google Analytics feature): Google Signals consists of session data from websites and apps that Google associates with users who are signed in to their Google Accounts and have enabled Ads Personalisation. This association of data with signed-in users is used to enable cross-device reporting, cross-device remarketing and cross-device conversion measurement. This includes: cross-platform reporting – linking data across devices and activities from different sessions using your User ID or Google Signals data, enabling an understanding of user behaviour at each step of the conversion process, from first contact through conversion and beyond; remarketing with Google Analytics – creating remarketing audiences from Google Analytics data and sharing these audiences with linked advertising accounts; demographics and interests – Google Analytics collects additional information concerning demographics and interests of users who are signed in to their Google Accounts and have enabled Ads Personalisation; service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; legal basis: consent (Art. 6(1), first sentence, point (a) GDPR); website: https://support.google.com/analytics/answer/7532985?hl=en; privacy policy: https://business.safety.google/privacy/; data processing agreement: https://business.safety.google/adsprocessorterms/; basis for third-country transfers: EU/EEA – Data Privacy Framework (DPF), Standard Contractual Clauses (https://business.safety.google/adsprocessorterms); Switzerland – Data Privacy Framework (DPF), Standard Contractual Clauses (https://business.safety.google/adsprocessorterms); further information: https://business.safety.google/adsservices/ (types of processing and data processed).
Online Marketing
We process personal data for online marketing purposes. This may include, in particular, the marketing of advertising space or the presentation of advertising and other content (collectively, “Content”) based on users’ potential interests and measurement of the effectiveness of such Content.
For these purposes, user profiles are created and stored in a file (a “cookie”), or comparable procedures are used to store user information relevant to the presentation of the aforementioned Content. This information may include, for example, content viewed, websites visited, online networks used, communication partners and technical information such as the browser used, the computer system used, and information on times of use and functions used. Where users have consented to the collection of location data, such data may also be processed.
Users’ IP addresses are also stored. However, we use available IP masking procedures (i.e. pseudonymisation by shortening the IP address) to protect users. As a general rule, no directly identifying user data (such as email addresses or names) is stored as part of online marketing procedures; instead, pseudonyms are used. This means that neither we nor the providers of online marketing procedures know the users’ actual identities, but only the information stored in their profiles.
The information contained in profiles is generally stored in cookies or by comparable means. These cookies may subsequently also be read on other websites using the same online marketing procedure and analysed for the purpose of displaying Content, as well as supplemented with additional data and stored on the server of the online marketing service provider.
In exceptional cases, it may be possible to associate directly identifying data with profiles, particularly where users are members of a social network whose online marketing procedures we use and where the network links users’ profiles with the aforementioned information. Please note that users may enter into additional agreements with providers, for example by giving consent during registration.
As a rule, we only receive access to aggregated information about the success of our advertisements. However, as part of conversion measurement, we can determine which of our online marketing procedures resulted in a conversion, for example the conclusion of a contract with us. Conversion measurement is used solely to analyse the success of our marketing activities.
Unless otherwise stated, please assume that cookies used for these purposes are stored for a period of two years.
Information on legal bases
Where we ask users for consent to the use of third-party providers, the legal basis for data processing is consent. Otherwise, user data is processed on the basis of our legitimate interests (i.e. our interest in efficient, economical and user-friendly services). In this context, we also refer you to the information concerning the use of cookies in this Privacy Policy.
Information on withdrawal and objection
We refer to the privacy information of the respective providers and the objection options (“opt-out”) stated for those providers. Where no explicit opt-out option is specified, you may disable cookies in your browser settings. This may, however, restrict functions of our Online Offering. We therefore additionally recommend the following opt-out options, which are offered for the relevant regions:
- Europe: https://youronlinechoices.eu/.
- Canada: https://youradchoices.ca/.
- USA: https://optout.aboutads.info/.
- Cross-regional: https://optout.aboutads.info/.
- Types of data processed: Content data (e.g. text or image-based messages and posts and related information such as authorship or time of creation); usage data (e.g. page views and time spent, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions); meta, communication and procedural data (e.g. IP addresses, time information, identification numbers, persons involved); event data (Facebook) (“Event Data” means information sent to Meta, for example via the Meta Pixel, apps or other channels, relating to individuals or their actions. This may include details of website visits, interactions with content and functions, app installations and product purchases. Event Data is processed for the purpose of creating audiences for content and advertising messages (Custom Audiences). Event Data does not include actual content such as comments, login information or contact information such as names, email addresses or telephone numbers. Meta deletes Event Data after a maximum of two years, and audiences created from such data cease to exist when our Meta user accounts are deleted.).
- Data subjects: Users (e.g. website visitors, users of online services).
- Purposes of processing and legitimate interests: Reach measurement (e.g. access statistics, recognition of returning visitors); tracking (e.g. interest- or behaviour-based profiling, use of cookies); conversion measurement (measuring the effectiveness of marketing measures); audience building; marketing; profiles containing user-related information (creating user profiles); provision of our Online Offering and user-friendliness; remarketing.
- Retention and deletion: Deletion in accordance with the information in the section “General Information on Data Retention and Deletion”. Cookies may be stored for up to two years (unless otherwise stated, cookies and comparable storage methods may be stored on users’ devices for a period of two years).
- Security measures: IP masking (pseudonymisation of the IP address).
- Legal basis: Consent (Art. 6(1), first sentence, point (a) GDPR).
Further information on processing operations, procedures and services
- Meta Pixel and audience building (Custom Audiences): With the help of the Meta Pixel (or comparable functions for transmitting Event Data or contact information via interfaces in apps), Meta can, among other things, identify visitors to our Online Offering as an audience for the display of advertisements (“Meta Ads”). We therefore use the Meta Pixel to display the Meta Ads placed by us only to users on Meta platforms and within services of partners cooperating with Meta (the “Audience Network”, https://www.facebook.com/audiencenetwork/) who have shown an interest in our Online Offering or who have certain characteristics (e.g. an interest in particular topics or products inferred from websites visited) that we transmit to Meta (“Custom Audiences”). We also use the Meta Pixel to help ensure that our Meta Ads correspond to users’ potential interests and are not perceived as intrusive. In addition, the Meta Pixel enables us to measure the effectiveness of Meta Ads for statistical and market research purposes by determining whether users were redirected to our website after clicking on a Meta Ad (“conversion measurement”); service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; legal basis: consent pursuant to Art. 6(1), first sentence, point (a) GDPR in conjunction with Section 25(1) TDDDG; website: https://www.facebook.com; privacy policy: https://www.facebook.com/privacy/policy/; data processing agreement: https://www.facebook.com/legal/terms/dataprocessing; basis for third-country transfers: EU/EEA – Data Privacy Framework (DPF), Standard Contractual Clauses (https://www.facebook.com/legal/EU_data_transfer_addendum); Switzerland – Data Privacy Framework (DPF), Standard Contractual Clauses (https://www.facebook.com/legal/EU_data_transfer_addendum); further information: Users’ Event Data, i.e. information concerning behaviour and interests, is processed for targeted advertising and audience building on the basis of the agreement on joint controllership (“Controller Addendum”, https://www.facebook.com/legal/controller_addendum). Joint controllership is limited to the collection and transmission of data to Meta Platforms Ireland Limited, an EU-based company. Further processing is the sole responsibility of Meta Platforms Ireland Limited, including in particular any transfer of data to its parent company Meta Platforms, Inc. in the United States (on the basis of Standard Contractual Clauses entered into between Meta Platforms Ireland Limited and Meta Platforms, Inc.).
- Facebook Ads: Placement of advertisements within the Facebook platform and analysis of advertising results; service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; legal basis: consent (Art. 6(1), first sentence, point (a) GDPR); website: https://www.facebook.com; privacy policy: https://www.facebook.com/privacy/policy/; basis for third-country transfers: EU/EEA – Data Privacy Framework (DPF); Switzerland – Data Privacy Framework (DPF); opt-out: We refer to the privacy and advertising settings in users’ profiles on Facebook platforms and to Facebook’s consent procedures and contact options for exercising rights of access and other data subject rights, as described in Facebook’s Privacy Policy; further information: Users’ Event Data, i.e. information concerning behaviour and interests, is processed for targeted advertising and audience building on the basis of the agreement on joint controllership (“Controller Addendum”, https://www.facebook.com/legal/controller_addendum). Joint controllership is limited to the collection and transmission of data to Meta Platforms Ireland Limited, an EU-based company. Further processing is the sole responsibility of Meta Platforms Ireland Limited, including in particular any transfer of data to its parent company Meta Platforms, Inc. in the United States (on the basis of Standard Contractual Clauses entered into between Meta Platforms Ireland Limited and Meta Platforms, Inc.).
- Facebook Conversions API: We use Facebook’s “Conversions API”. The Conversions API is an interface through which Event Data is sent directly from our servers to Facebook. Its functionality and the processing of data via the Conversions API correspond to the functionality and processing involved in the use of the Facebook Pixel. We therefore refer in this respect to the privacy information concerning the Facebook Pixel and audience building; legal basis: consent (Art. 6(1), first sentence, point (a) GDPR).
Social Media Presences
We maintain online presences within social networks and process user data in this context in order to communicate with users active there or to provide information about us.
Please note that user data may be processed outside the European Union. This may result in risks for users, for example because it may make it more difficult to enforce users’ rights.
Furthermore, user data within social networks is generally processed for market research and advertising purposes. For example, usage profiles may be created on the basis of users’ usage behaviour and interests derived from it. These usage profiles may in turn be used, for example, to display advertisements within and outside the networks that are presumed to correspond to users’ interests. Cookies are therefore generally stored on users’ computers in which usage behaviour and interests are recorded. In addition, data may be stored in usage profiles independently of the devices used by users, particularly where they are members of the relevant platforms and logged in there.
For a detailed description of the respective forms of processing and options to object (opt-out), please refer to the privacy policies and information provided by the operators of the respective networks.
With regard to access requests and the exercise of data subject rights, we also point out that these can generally be asserted most effectively against the providers themselves. Only the providers have direct access to users’ data and can take appropriate measures and provide information directly. If you nevertheless require assistance, you can contact us.
- Types of data processed: Contact data (e.g. postal and email addresses or telephone numbers); content data (e.g. text or image-based messages and posts and related information such as authorship or time of creation); usage data (e.g. page views and time spent, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions); meta, communication and procedural data (e.g. IP addresses, time information, identification numbers, persons involved).
- Data subjects: Users (e.g. website visitors, users of online services).
- Purposes of processing and legitimate interests: Communication; feedback (e.g. collecting feedback via online forms); public relations.
- Retention and deletion: Deletion in accordance with the information in the section “General Information on Data Retention and Deletion”.
- Legal basis: Legitimate interests (Art. 6(1), first sentence, point (f) GDPR).
Further information on processing operations, procedures and services
- Instagram: Social network enabling users to share photos and videos, comment on and favourite posts, send messages and follow profiles and pages; service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; legal basis: legitimate interests (Art. 6(1), first sentence, point (f) GDPR); website: https://www.instagram.com; privacy policy: https://privacycenter.instagram.com/policy/; basis for third-country transfers: EU/EEA – Data Privacy Framework (DPF); Switzerland – Data Privacy Framework (DPF).
- Facebook Pages: Profiles within the Facebook social network – The controller is jointly responsible with Meta Platforms Ireland Limited for the collection and transmission of data relating to visitors to our Facebook Page (“Fan Page”). This includes, in particular, information concerning user behaviour (e.g. content viewed or interacted with and actions taken), as well as device information (e.g. IP address, operating system, browser type, language settings and cookie data). Further details are available in Facebook’s Privacy Policy: https://www.facebook.com/privacy/policy/. Facebook also uses this data to provide us with statistical evaluations through the “Page Insights” service, which provide information about how people interact with our Page and its content. This is based on an agreement with Facebook (“Page Insights Controller Addendum”: https://www.facebook.com/legal/terms/page_controller_addendum), which regulates, among other things, security measures and the exercise of data subject rights. Further information is available at https://www.facebook.com/legal/terms/information_about_page_insights_data. Users may therefore submit access or deletion requests directly to Facebook. Users’ rights, including in particular rights of access, erasure, objection and complaint to a supervisory authority, remain unaffected. Joint controllership is limited exclusively to the collection of data by Meta Platforms Ireland Limited (EU). Meta Platforms Ireland Limited is solely responsible for further processing, including any transfer to Meta Platforms Inc. in the United States; service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; legal basis: legitimate interests (Art. 6(1), first sentence, point (f) GDPR); website: https://www.facebook.com; privacy policy: https://www.facebook.com/privacy/policy/; basis for third-country transfers: EU/EEA – Data Privacy Framework (DPF), Standard Contractual Clauses (https://www.facebook.com/legal/EU_data_transfer_addendum); Switzerland – Data Privacy Framework (DPF), Standard Contractual Clauses (https://www.facebook.com/legal/EU_data_transfer_addendum).
- LinkedIn: Social network – We are jointly responsible with LinkedIn Ireland Unlimited Company for the collection (but not further processing) of visitor data used to create “Page Insights” (statistics) for our LinkedIn profiles. This data includes information concerning the types of content users view or interact with and the actions they take. Details are also collected about the devices used, such as IP addresses, operating system, browser type, language settings and cookie data, as well as information from user profiles such as job function, country, industry, seniority level, company size and employment status. Information on LinkedIn’s processing of user data is available in LinkedIn’s Privacy Policy: https://www.linkedin.com/legal/privacy-policy.We have entered into a specific agreement with LinkedIn Ireland (“Page Insights Joint Controller Addendum”, https://legal.linkedin.com/pages-joint-controller-addendum), which regulates, in particular, the security measures LinkedIn must comply with and under which LinkedIn has agreed to fulfil data subject rights (i.e. users can, for example, submit access or deletion requests directly to LinkedIn). Users’ rights, in particular rights of access, erasure, objection and complaint to the competent supervisory authority, are not restricted by the arrangements with LinkedIn. Joint controllership is limited to the collection and transmission of data to LinkedIn Ireland Unlimited Company, an EU-based company. Further processing is carried out solely by LinkedIn Ireland Unlimited Company, in particular any transfer of data to its parent company LinkedIn Corporation in the United States; service provider: LinkedIn Ireland Unlimited Company, Wilton Plaza, Dublin 2, Ireland; legal basis: legitimate interests (Art. 6(1), first sentence, point (f) GDPR); website: https://www.linkedin.com; privacy policy: https://www.linkedin.com/legal/privacy-policy; basis for third-country transfers: EU/EEA – Data Privacy Framework (DPF), Standard Contractual Clauses (https://www.linkedin.com/legal/privacy-policy); Switzerland – Data Privacy Framework (DPF), Standard Contractual Clauses (https://www.linkedin.com/legal/privacy-policy); opt-out: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.
- TikTok: Social network enabling users to share photos and videos, comment on and favourite posts, send messages and follow accounts; service providers: TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland, and TikTok Information Technologies UK Limited, Kaleidoscope, 4 Lindsey Street, London, United Kingdom, EC1A 9HP; legal basis: legitimate interests (Art. 6(1), first sentence, point (f) GDPR); website: https://www.tiktok.com; privacy policy: https://www.tiktok.com/legal/page/eea/privacy-policy/en; data processing agreement: Provided by the service provider.
- YouTube: Social network and video platform; service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; legal basis: legitimate interests (Art. 6(1), first sentence, point (f) GDPR); privacy policy: https://business.safety.google/privacy/; basis for third-country transfers: EU/EEA – Data Privacy Framework (DPF); Switzerland – Data Privacy Framework (DPF); opt-out: https://myadcenter.google.com/.
Plug-ins, Embedded Functions and Content
We integrate functional and content elements into our Online Offering that are obtained from the servers of their respective providers (hereinafter referred to as “Third-Party Providers”). These may include, for example, graphics, videos or maps (collectively referred to as “Content”).
Integration always requires the Third-Party Providers of such Content to process users’ IP addresses, as they would otherwise be unable to send the Content to the users’ browsers. The IP address is therefore required in order to display such Content or functions. We endeavour to use only Content whose respective providers use the IP address solely for the purpose of delivering the Content. Third-Party Providers may also use so-called pixel tags (invisible graphics, also referred to as “web beacons”) for statistical or marketing purposes. Pixel tags can be used to evaluate information such as visitor traffic on the pages of this website. Pseudonymous information may also be stored in cookies on users’ devices and may include, among other things, technical information concerning the browser and operating system, referring websites, time of visit and further information concerning use of our Online Offering; such information may also be combined with information from other sources.
Information on legal bases
Where we ask users for consent to the use of Third-Party Providers, the legal basis for data processing is consent. Otherwise, user data is processed on the basis of our legitimate interests (i.e. our interest in efficient, economical and user-friendly services). In this context, we also refer you to the information concerning the use of cookies in this Privacy Policy.
- Types of data processed: Usage data (e.g. page views and time spent, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions); meta, communication and procedural data (e.g. IP addresses, time information, identification numbers, persons involved).
- Data subjects: Users (e.g. website visitors, users of online services).
- Purposes of processing and legitimate interests: Provision of our Online Offering and user-friendliness; security measures.
- Retention and deletion: Deletion in accordance with the information in the section “General Information on Data Retention and Deletion”. Cookies may be stored for up to two years (unless otherwise stated, cookies and comparable storage methods may be stored on users’ devices for a period of two years).
- Legal bases: Consent (Art. 6(1), first sentence, point (a) GDPR); legitimate interests (Art. 6(1), first sentence, point (f) GDPR).
Further information on processing operations, procedures and services
hCaptcha
We use hCaptcha in our contact and application forms to verify whether entries are made by a natural person or by an automated program. The service is used to protect our forms and IT systems against spam, automated submissions and other misuse.
hCaptcha is used only in connection with access to and use of the relevant contact and application forms. In this context, the IP address, information concerning the browser and terminal device used, time and duration of use, and information about interaction with the hCaptcha element may in particular be processed. Processing is based on our legitimate interest in the security and functionality of our forms and in preventing automated and abusive submissions pursuant to Art. 6(1), first sentence, point (f) GDPR. Where information is stored on or read from the terminal device in order to provide a form function expressly requested by the user and this is strictly technically necessary, this is carried out on the basis of Section 25(2) no. 2 TDDDG.
The service provider is Intuition Machines, Inc., 350 Alabama Street, San Francisco, CA 94110, USA. Further information on data processing is available at https://www.hcaptcha.com/privacy. According to the provider, it is certified under the EU-US Data Privacy Framework.
Application Procedures
The application procedure requires applicants to provide us with the data necessary for their assessment and selection. The information required results from the job description or, in the case of online forms, from the information stated there.
The information normally required includes personal information such as name, address, contact details and evidence of the qualifications required for a position. Upon request, we will also be pleased to inform applicants which information is required.
Where available, applicants may submit their applications via our online form, which is encrypted in accordance with the current state of the art. Alternatively, applications may be sent to us by email. Please note, however, that emails on the internet are generally not transmitted with end-to-end encryption. Although emails are usually encrypted during transmission, they are not encrypted on the servers from which they are sent and received. We therefore cannot accept responsibility for the security of an application during its transmission between the sender and our server.
For the purposes of applicant search, submission of applications and applicant selection, we may use applicant management or recruitment software, platforms and services provided by third parties in compliance with statutory requirements.
Applicants are welcome to contact us regarding the manner in which an application should be submitted or to send their application to us by post.
Processing of special categories of data
Where special categories of personal data (Art. 9(1) GDPR, e.g. health data such as severe disability status or ethnic origin) are requested from or provided by applicants in the context of the application procedure, such data is processed where necessary to enable the controller or the data subject to exercise rights and comply with obligations arising from employment law and social security and social protection law, for the protection of the vital interests of applicants or other persons, or for purposes of preventive or occupational medicine, assessment of an employee’s working capacity, medical diagnosis, provision of health or social care or treatment, or management of health or social care systems and services.
Deletion of data
Where an application is successful, application data may be further processed for the purpose of carrying out the employment relationship and transferred to the personnel file. The legal basis for this is Section 26(1), first sentence, BDSG.
Where no employment relationship is established or an application is withdrawn, application data is generally deleted no later than six months after completion of the application procedure or withdrawal of the application. Temporary further retention is based on Art. 6(1), first sentence, point (f) GDPR. Our legitimate interest lies in documenting the application procedure and in the establishment, exercise or defence of potential legal claims.
Where applicants object to further retention, the data is deleted earlier unless overriding legitimate grounds for further retention exist.
Longer retention takes place only where applicants have expressly consented to inclusion in an applicant pool, where the data is required for pending or specifically threatened legal proceedings, or where statutory retention obligations apply. Invoices and receipts relating to any reimbursement of application expenses are retained in accordance with the applicable retention periods under commercial and tax law.
Inclusion in an applicant pool
Where offered, inclusion in an applicant pool is based on consent. Applicants are informed that their consent to inclusion in the talent pool is voluntary, has no effect on the ongoing application procedure and may be withdrawn at any time with effect for the future.
- Types of data processed: Master data (e.g. full name, residential address, contact information, customer number, etc.); contact data (e.g. postal and email addresses or telephone numbers); content data (e.g. text or image-based messages and posts and related information such as authorship or time of creation); applicant data (e.g. personal information, postal and contact addresses, application documents and the information contained therein, such as cover letters, CVs, certificates and other information relating to the applicant’s person or qualifications provided with regard to a specific position or voluntarily).
- Data subjects: Applicants.
- Purposes of processing and legitimate interests: Application procedure (establishment and any subsequent performance and possible later termination of the employment relationship).
- Retention and deletion: Deletion in accordance with the information in the section “General Information on Data Retention and Deletion”.
- Legal bases: Processing for the purpose of deciding whether to establish an employment relationship (Section 26(1), first sentence, BDSG); voluntary consent where required (Section 26(2) BDSG in conjunction with Art. 6(1), first sentence, point (a) GDPR); processing of special categories of personal data where required under employment law (Section 26(3) BDSG in conjunction with Art. 9(2), point (b) GDPR) or on the basis of explicit consent (Section 26(2) BDSG in conjunction with Art. 9(2), point (a) GDPR); pursuit of legitimate interests following completion of an unsuccessful application procedure, in particular the establishment, exercise or defence of legal claims (Art. 6(1), first sentence, point (f) GDPR).
Definitions
This section provides an overview of terms used in this Privacy Policy. Where terms are defined by law, the statutory definitions apply. The explanations below are intended primarily to aid understanding.
- Master data: Master data comprises essential information required to identify and manage contractual partners, user accounts, profiles and similar assignments. This data may include personal and demographic details such as names, contact information (addresses, telephone numbers, email addresses), dates of birth and specific identifiers (user IDs). Master data provides the basis for formal interaction between persons and services, institutions or systems by enabling clear assignment and communication.
- Content data: Content data comprises information generated in connection with the creation, editing and publication of content of all kinds. This category may include text, images, videos, audio files and other multimedia content published on different platforms and media. Content data is not limited to the content itself but also includes metadata providing information about the content, such as tags, descriptions, author information and publication dates.
- Click tracking: Click tracking makes it possible to trace users’ movements within an entire Online Offering. As the results of these tests are more accurate when users’ interactions can be tracked over a certain period (e.g. to determine whether a user returns), cookies are generally stored on users’ devices for these testing purposes.
- Contact data: Contact data is essential information that enables communication with persons or organisations. It includes, among other things, telephone numbers, postal addresses and email addresses, as well as communication identifiers such as social media handles and instant messaging identifiers.
- Conversion measurement: Conversion measurement (also referred to as “conversion tracking”) is a procedure used to determine the effectiveness of marketing measures. As a rule, a cookie is stored on users’ devices on the websites where the marketing measures take place and subsequently retrieved on the destination website. This allows us, for example, to determine whether advertisements placed by us on other websites were successful.
- Meta, communication and procedural data: Meta, communication and procedural data are categories containing information about the way data is processed, transmitted and managed. Metadata, also known as data about data, includes information describing the context, origin and structure of other data. This may include file size, creation date, document author and change histories. Communication data records the exchange of information between users across different channels, such as email traffic, call logs, social network messages and chat histories, including persons involved, timestamps and transmission routes. Procedural data describes processes and workflows within systems or organisations, including workflow documentation, records of transactions and activities, and audit logs used to trace and verify operations.
- Usage data: Usage data refers to information recording how users interact with digital products, services or platforms. It includes a wide range of information showing how users use applications, which functions they prefer, how long they remain on certain pages and which paths they take through an application. Usage data may also include frequency of use, timestamps of activities, IP addresses, device information and location data. It is particularly valuable for analysing user behaviour, optimising user experiences, personalising content and improving products or services. Usage data also plays an important role in identifying trends, preferences and potential problem areas within digital offerings.
- Personal data: “Personal data” means any information relating to an identified or identifiable natural person (“data subject”). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data, an online identifier (e.g. a cookie) or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
- Profiles containing user-related information: The processing of “profiles containing user-related information”, or “profiles” for short, comprises any form of automated processing of personal data in which such personal data is used to analyse, evaluate or predict certain personal aspects relating to a natural person. Depending on the type of profiling, this may include different information concerning demographics, behaviour and interests, such as interaction with websites and their content, and may be used, for example, to predict interest in certain content or products, click behaviour on a website or location. Cookies and web beacons are frequently used for profiling purposes.
- Log data: Log data is information about events or activities recorded in a system or network. This data typically contains information such as timestamps, IP addresses, user actions, error messages and other details concerning the use or operation of a system. Log data is frequently used to analyse system problems, monitor security or prepare performance reports.
- Reach measurement: Reach measurement (also referred to as web analytics) is used to evaluate visitor traffic to an Online Offering and may include visitors’ behaviour or interests in certain information, such as website content. Reach analysis enables operators of online offerings, for example, to determine when users visit their websites and which content interests them. This allows website content to be better adapted to visitors’ needs. Pseudonymous cookies and web beacons are frequently used for reach analysis to recognise returning visitors and obtain more accurate analyses of use of an Online Offering.
- Remarketing: “Remarketing” or “retargeting” refers, for example, to recording for advertising purposes which products a user has shown an interest in on a website so that the user can be reminded of those products on other websites, for example through advertisements.
- Tracking: “Tracking” refers to the ability to trace users’ behaviour across multiple online offerings. As a rule, behaviour and interest information concerning the online offerings used is stored in cookies or on the servers of tracking technology providers (so-called profiling). This information can subsequently be used, for example, to display advertisements to users that are likely to match their interests.
- Controller: The “controller” is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
- Processing: “Processing” means any operation or set of operations performed on personal data, whether or not by automated means. The term is broad and covers virtually any handling of data, including collection, analysis, storage, transmission and deletion.
- Contract data: Contract data is specific information relating to the formalisation of an agreement between two or more parties. It documents the terms under which services or products are provided, exchanged or sold. This category of data is essential for managing and fulfilling contractual obligations and includes both identification of the contracting parties and the specific terms and conditions of the agreement. Contract data may include the start and end dates of the contract, the type of services or products agreed, pricing arrangements, payment terms, termination rights, extension options and special terms or clauses. It serves as the legal basis for the relationship between the parties and is essential for clarifying rights and obligations, enforcing claims and resolving disputes.
- Payment data: Payment data comprises all information required to process payment transactions between buyers and sellers. Such data is essential for e-commerce, online banking and any other form of financial transaction. It may include details such as credit card numbers, bank details, payment amounts, transaction data, verification numbers and billing information. Payment data may also include information concerning payment status, chargebacks, authorisations and fees.
- Audience building: Audience building (“Custom Audiences”) refers to defining audiences for advertising purposes, for example for displaying advertisements. Based on a user’s interest in certain products or topics online, it may be inferred that the user is interested in advertisements for similar products or the online shop in which the products were viewed. “Lookalike Audiences” (or similar audiences), in turn, refers to displaying content deemed suitable to users whose profiles or presumed interests are similar to those of users for whom profiles have been created. Cookies and web beacons are generally used to create Custom Audiences and Lookalike Audiences.