Privacy Policy
This English version is a translation provided for ease of understanding only. The German-language version of this privacy policy is the sole legally binding version. In the event of any discrepancy between the two, the German version prevails.
With the following privacy policy, we would like to explain to you which types of your personal data (hereinafter also referred to in short as “data”) we process, for which purposes, and to what extent. This privacy policy applies to all processing of personal data carried out by us, both in the course of providing our services and, in particular, on our websites, in mobile applications, and within external online presences, such as our social media profiles (hereinafter collectively referred to as our “online offering”).
The terms used are not gender-specific.
Controller
Inter-Harz GmbH
Rostock-Koppel 10
25365 Klein Offenseth-Sparrieshoop, Germany
Authorized representatives: Managing Directors: Klaus H. Harz, Lothar Brandt
E-Mail-Adresse: info@interharz.de
Telefon: +49 4121 2354-600
Legal notice: https://interharz.de/de/impressum/
Data Protection Officer contact
QuaSi Consult GbR
Tina Walloschek
datenschutz[at]quasi-consult.de
Relevant legal bases
Relevant legal bases under the GDPR: Below you will find an overview of the legal bases of the GDPR on the basis of which we process personal data. Please note that, in addition to the provisions of the GDPR, national data protection requirements may apply in your or our country of residence or domicile. Should more specific legal bases also be relevant in individual cases, we will inform you of these in the privacy policy.
- Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR) – The data subject has given their consent to the processing of personal data relating to them for one specific purpose or several specific purposes.
- Performance of a contract and pre-contractual requests (Art. 6 para. 1 sentence 1 lit. b) GDPR) – Processing is necessary for the performance of a contract to which the data subject is a party, or for the implementation of pre-contractual measures carried out at the request of the data subject.
- Legal obligation (Art. 6 para. 1 sentence 1 lit. c) GDPR) – Processing is necessary for compliance with a legal obligation to which the controller is subject.
- Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR) – Processing is necessary to safeguard the legitimate interests of the controller or of a third party, provided that the interests, fundamental rights, and fundamental freedoms of the data subject requiring the protection of personal data do not override those interests.
- Application procedure as a pre-contractual or contractual relationship (Art. 6 para. 1 sentence 1 lit. b) GDPR) – Insofar as, in the course of the application procedure, special categories of personal data within the meaning of Art. 9 para. 1 GDPR (e.g., health data, such as severe disability status or ethnic origin) are requested from applicants so that the controller or the data subject can exercise the rights and comply with the obligations arising from employment law and social security and social protection law, their processing is carried out pursuant to Art. 9 para. 2 lit. b GDPR; in the case of the protection of vital interests of applicants or other persons pursuant to Art. 9 para. 2 lit. c GDPR; or for the purposes of preventive healthcare or occupational medicine, for the assessment of the employee’s working capacity, for medical diagnosis, for the provision of care or treatment in the health or social sector, or for the management of health or social care systems and services pursuant to Art. 9 para. 2 lit. h GDPR. In the case of a communication of special categories of data based on voluntary consent, their processing is carried out on the basis of Art. 9 para. 2 lit. a GDPR.
National data protection regulations in Germany: In addition to the data protection regulations of the GDPR, national regulations on data protection apply in Germany. These include, in particular, the Federal Data Protection Act (Bundesdatenschutzgesetz – BDSG). In particular, the BDSG contains special provisions on the right of access, the right to erasure, the right to object, the processing of special categories of personal data, processing for other purposes, and transmission as well as automated decision-making in individual cases including profiling. Furthermore, the data protection laws of the individual federal states (Landesdatenschutzgesetze) may apply.
Security Measures
In accordance with the legal requirements, and taking into account the state of the art, the implementation costs, and the nature, scope, circumstances, and purposes of the processing, as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, we take appropriate technical and organizational measures to ensure a level of protection appropriate to the risk.
The measures include, in particular, safeguarding the confidentiality, integrity, and availability of data by controlling physical and electronic access to the data as well as access to, input of, disclosure of, safeguarding of the availability of, and separation of the data. Furthermore, we have established procedures that ensure the exercise of data subjects’ rights, the erasure of data, and responses to threats to the data. In addition, we take the protection of personal data into account as early as the development or selection of hardware, software, and procedures, in accordance with the principle of data protection by design and by default.
Securing online connections using TLS/SSL encryption technology (HTTPS): To protect the data of users transmitted via our online services against unauthorized access, we use TLS/SSL encryption technology. Secure Sockets Layer (SSL) and Transport Layer Security (TLS) are the cornerstones of secure data transmission on the internet. These technologies encrypt the information transmitted between the website or app and the user’s browser (or between two servers), thereby protecting the data against unauthorized access. TLS, as the further developed and more secure version of SSL, ensures that all data transmissions meet the highest security standards. When a website is secured by an SSL/TLS certificate, this is indicated by the display of HTTPS in the URL. This serves as an indicator to users that their data is transmitted securely and in encrypted form.
Transmission of personal data
In the course of our processing of personal data, it may happen that this data is transmitted to, or disclosed to, other bodies, companies, legally independent organizational units, or persons. Recipients of this data may include, for example, service providers commissioned with IT tasks, or providers of services and content that are integrated into a website. In such cases, we observe the legal requirements and, in particular, conclude appropriate contracts or agreements with the recipients of your data that serve to protect your data.
Data transmission within the organization: We may transmit personal data to other departments or units within our organization, or grant them access to it. Insofar as the data is shared for administrative purposes, it is based on our legitimate business and commercial interests, or it takes place where it is necessary for the performance of our contract-related obligations, or where there is consent from the data subjects or a legal permission.
International data transfer
Data processing in third countries: Insofar as we transmit data to a third country (i.e., outside the European Union (EU) or the European Economic Area (EEA)), or this occurs in the course of using third-party services or disclosing or transmitting data to other persons, bodies, or companies (which becomes apparent from the postal address of the respective provider, or if the privacy policy expressly refers to the transfer of data to third countries), this is always done in accordance with the legal requirements.
For data transfers to the USA, we rely primarily on the Data Privacy Framework (DPF), which was recognized as a secure legal framework by an adequacy decision of the EU Commission dated 10 July 2023. In addition, we have concluded standard contractual clauses with the respective providers that comply with the requirements of the EU Commission and establish contractual obligations to protect your data.
This twofold safeguard ensures comprehensive protection of your data: the DPF forms the primary level of protection, while the standard contractual clauses serve as an additional safeguard. Should any changes occur within the framework of the DPF, the standard contractual clauses will take effect as a reliable fallback option. In this way, we ensure that your data always remains adequately protected, even in the event of any political or legal changes.
For the individual service providers, we inform you whether they are certified under the DPF and whether standard contractual clauses are in place. Further information on the DPF and a list of the certified companies can be found on the website of the U.S. Department of Commerce at https://www.dataprivacyframework.gov/ .
For data transfers to other third countries, corresponding security measures apply, in particular standard contractual clauses, explicit consent, or legally required transfers. Information on third-country transfers and applicable adequacy decisions can be found in the information provided by the EU Commission: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection_en?prefLang=de.
General information on data storage and erasure
We erase personal data that we process in accordance with the legal provisions as soon as the underlying consents are withdrawn or there are no further legal bases for the processing. This concerns cases in which the original purpose of the processing no longer applies or the data is no longer required. Exceptions to this rule apply where legal obligations or special interests require a longer retention or archiving of the data.
In particular, data that must be retained for commercial or tax law reasons, or whose storage is necessary for the pursuit of legal claims or for the protection of the rights of other natural or legal persons, must be archived accordingly.
Our privacy notices contain additional information on the retention and erasure of data that applies specifically to certain processing operations.
Where there are several indications of the retention period or erasure deadlines for a given piece of data, the longest period is always decisive. Data that is no longer retained for the originally intended purpose, but rather due to legal requirements or other reasons, is processed by us exclusively for the reasons that justify its retention.
Retention and erasure of data: The following general periods apply to retention and archiving under German law:
- 10 years – Retention period for books and records, annual financial statements, inventories, management reports, opening balance sheets, and the working instructions and other organizational documents required to understand them (§ 147 para. 1 no. 1 in conjunction with para. 3 AO, § 257 para. 1 no. 1 in conjunction with para. 4 HGB).
- 8 years – Accounting vouchers, such as invoices and expense receipts (§ 147 para. 1 no. 4 and 4a in conjunction with para. 3 sentence 1 AO, § 14b para. 1 UStG, and § 257 para. 1 no. 4 in conjunction with para. 4 HGB).
- 6 years – Other business documents: received commercial or business letters, reproductions of dispatched commercial or business letters, and other documents insofar as they are of relevance for taxation, e.g., hourly wage slips, cost accounting sheets, calculation documents, price labels, but also payroll accounting documents insofar as they are not already accounting vouchers, and cash register receipts (§ 147 para. 1 no. 2, 3, 5 in conjunction with para. 3 AO, § 257 para. 1 no. 2 and 3 in conjunction with para. 4 HGB).
- 3 years – Data required in order to take into account potential warranty and compensation claims or similar contractual claims and rights, as well as to process related inquiries, based on past business experience and customary industry practices, is stored for the duration of the regular statutory limitation period of three years (§§ 195, 199 BGB).
Commencement of the period at the end of the year: If a period does not begin expressly on a specific date and is at least one year, it starts automatically at the end of the calendar year in which the event triggering the period occurred. In the case of ongoing contractual relationships in the course of which data is stored, the event triggering the period is the point in time at which the termination or other ending of the legal relationship takes effect.
Rights of data subjects
Rights of data subjects under the GDPR: As a data subject, you have various rights under the GDPR, which arise in particular from Art. 15 to 21 GDPR:
- Right to object: You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is carried out on the basis of Art. 6 para. 1 lit. e or f GDPR; this also applies to profiling based on these provisions. Where personal data concerning you is processed for the purposes of direct marketing, you have the right to object at any time to the processing of personal data concerning you for the purposes of such marketing; this also applies to profiling insofar as it is connected with such direct marketing.
- Right to withdraw consent: You have the right to withdraw consent you have given at any time.
- Right of access: You have the right to request confirmation as to whether data concerning you is being processed, and to obtain access to this data as well as further information and a copy of the data in accordance with the legal requirements.
- Right to rectification: You have the right, in accordance with the legal requirements, to request the completion of data concerning you or the rectification of inaccurate data concerning you.
- Right to erasure and restriction of processing: You have the right, in accordance with the legal requirements, to request that data concerning you be erased without delay, or, alternatively, in accordance with the legal requirements, to request a restriction of the processing of the data.
- Right to data portability: You have the right, in accordance with the legal requirements, to receive data concerning you that you have provided to us in a structured, commonly used, and machine-readable format, or to request its transmission to another controller.
- Complaint to a supervisory authority: In accordance with the legal requirements and without prejudice to any other administrative or judicial remedy, you also have the right to lodge a complaint with a data protection supervisory authority, in particular a supervisory authority in the Member State of your habitual residence, the supervisory authority of your place of work, or the place of the alleged infringement, if you consider that the processing of personal data concerning you infringes the GDPR.
Business services
We process personal data of our contractual and business partners, such as customers, clients, prospective customers, suppliers, and other cooperation partners (collectively “contractual partners”), for the initiation, execution, and processing of contractual relationships as well as comparable legal relationships. This also includes pre-contractual measures carried out upon request, as well as communication in connection with the respective contractual relationship.
The processing serves, in particular, to fulfill our main and ancillary contractual obligations. These include the provision of the agreed services, any updating and information obligations, the handling of warranty and other performance defects, the processing of withdrawals, terminations of continuing obligations, reversals, refunds, as well as the handling of other contract-related declarations and inquiries. This covers both one-off contracts and ongoing contractual relationships.
In particular, we process master data such as name, address, and, where applicable, company; contact data such as email address and telephone number; contract and performance data such as the subject matter of the contract, contract term, order or transaction number; usage and performance data; payment and billing data; as well as communication content and histories. Insofar as necessary, we also process data disclosed or transmitted to us in the course of performing an order.
In addition, we process the data to safeguard our rights and to comply with legal obligations. This includes, in particular, commercial and tax retention obligations, documentation obligations, and, where applicable, verification and accountability obligations. Processing is also carried out on the basis of our legitimate interests in proper business management, internal administration, risk management, and IT security, as well as in the protection of our business operations and our contractual partners against misuse, threats to data, trade secrets, and other legally protected interests. This may also include the involvement of external service providers such as IT and telecommunications providers, transport and logistics companies, payment service providers, banks, tax and legal advisors, or other vicarious agents, insofar as this is necessary for the performance of the contract or for the fulfillment of legal obligations.
Personal data is disclosed to third parties exclusively insofar as this is necessary for the performance of the contract, for the implementation of pre-contractual measures, for safeguarding legitimate interests, or for the fulfillment of legal obligations. We provide separate information about any processing that goes beyond this, in particular for marketing purposes, within this privacy policy.
We inform contractual partners which data is required in individual cases at the time of data collection, for example through corresponding labeling in online forms or in personal contact.
The data is erased as soon as it is no longer required for the aforementioned purposes and no legal retention obligations preclude erasure. Statutory retention periods, in particular under commercial and tax law, may require longer storage. Data transmitted in the course of a specific order is erased by us after the completion of the order and the expiry of any retention periods, provided that there are no further legal or contractual obligations to store it.
The legal basis for the processing is Art. 6 para. 1 lit. b GDPR for the implementation of pre-contractual measures and for the performance of the respective contractual relationship, as well as Art. 6 para. 1 lit. c GDPR for the fulfillment of legal obligations. Insofar as the processing is based on legitimate interests, it is carried out on the basis of Art. 6 para. 1 lit. f GDPR. Insofar as the processing is based on Art. 6 para. 1 lit. f GDPR, it is carried out to safeguard our legitimate interests in a proper and efficient business organization, the internal administration and documentation of business transactions, the enforcement and defense of legal claims, ensuring IT and data security, the prevention of misuse and fraud, as well as the economic management and further development of our business operations. These interests consist, in particular, in ensuring secure and legally compliant business operations, as well as in safeguarding our entrepreneurial capacity to act.
- Types of data processed: Inventory data (e.g., full name, residential address, contact information, customer number, etc.); payment data (e.g., bank details, invoices, payment history); contact data (e.g., postal and email addresses or telephone numbers); contract data (e.g., subject matter of the contract, term, customer category).
- Data subjects: Service recipients and clients; prospective customers; business and contractual partners.
- Purposes of processing and legitimate interests: Provision of contractual services and fulfillment of contractual obligations; communication; office and organizational procedures; organizational and administrative procedures; business processes and commercial procedures.
- Retention and erasure: Erasure in accordance with the information provided in the section “General information on data storage and erasure.”
- Legal bases: Performance of a contract and pre-contractual requests (Art. 6 para. 1 sentence 1 lit. b) GDPR); legal obligation (Art. 6 para. 1 sentence 1 lit. c) GDPR); legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
Further information on processing operations, procedures, and services:
- Chemical industry: We process the data of customers, suppliers, business partners, prospective customers, and other contacts in order to distribute chemical products and related services and to conduct the associated business. This includes, in particular, communication and the handling of inquiries, the management of contract and order data, the coordination of deliveries and services, the organization of projects and appointments, and the documentation of business and production operations, insofar as this is necessary for carrying out the activity. Furthermore, we process personal data for customer and supplier management, for quality assurance, for complaint handling, for internal organization, for billing, and for the maintenance of business relationships. Insofar as necessary, we cooperate with service providers and other parties who support us, for example, in the areas of IT, logistics, office organization, or comparable support services. Legal bases: Performance of a contract and pre-contractual requests (Art. 6 para. 1 sentence 1 lit. b) GDPR), legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
Business processes and procedures
Personal data of service recipients and clients – including customers, clients or, in special cases, mandates, patients, or business partners, as well as other third parties – is processed in the course of contractual and comparable legal relationships and pre-contractual measures such as the initiation of business relationships. This data processing supports and facilitates commercial operations in areas such as customer management, sales, payment transactions, accounting, and project management.
The data collected serves to fulfill contractual obligations and to design operational processes efficiently. This includes the handling of business transactions, the management of customer relationships, the optimization of sales strategies, and ensuring internal invoicing and financial processes. In addition, the data supports the safeguarding of the controller’s rights and promotes administrative tasks and the organization of the company.
Personal data may be disclosed to third parties insofar as this is necessary for the fulfillment of the stated purposes or of legal obligations. After the expiry of statutory retention periods or where the purpose of the processing no longer applies, the data is erased. This also includes data that must be stored for longer due to tax and legal verification obligations.
- Types of data processed: Inventory data (e.g., full name, residential address, contact information, customer number, etc.); payment data (e.g., bank details, invoices, payment history); contact data (e.g., postal and email addresses or telephone numbers); content data (e.g., textual or pictorial messages and contributions as well as information relating to them, such as details of authorship or the time of creation); contract data (e.g., subject matter of the contract, term, customer category); log data (e.g., log files relating to logins or the retrieval of data or access times); meta, communication, and procedural data (e.g., IP addresses, time stamps, identification numbers, persons involved); usage data (e.g., page views and duration of visit, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions).
- Data subjects: Service recipients and clients; prospective customers; communication partners; business and contractual partners; third parties; customers.
- Purposes of processing and legitimate interests: Provision of contractual services and fulfillment of contractual obligations; office and organizational procedures; business processes and commercial procedures; communication; financial and payment management; information technology infrastructure (operation and provision of information systems and technical devices (computers, servers, etc.)); marketing; sales promotion.
- Retention and erasure: Erasure in accordance with the information provided in the section “General information on data storage and erasure.”
- Legal bases: Performance of a contract and pre-contractual requests (Art. 6 para. 1 sentence 1 lit. b) GDPR); legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); legal obligation (Art. 6 para. 1 sentence 1 lit. c) GDPR).
Further information on processing operations, procedures, and services:
- Customer management and customer relationship management (CRM): Procedures required in the course of customer management and customer relationship management (CRM) (e.g., customer acquisition in compliance with data protection requirements, measures to promote customer retention and loyalty, effective customer communication, complaint management and customer service with due regard for data protection, data management and analysis to support the customer relationship, administration of CRM systems, secure account management, customer segmentation, and target group formation); Legal bases: Performance of a contract and pre-contractual requests (Art. 6 para. 1 sentence 1 lit. b) GDPR), legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
- Contact management and contact maintenance: Procedures required in the course of the organization, maintenance, and safeguarding of contact information (e.g., the establishment and maintenance of a central contact database, regular updates of contact information, monitoring of data integrity, implementation of data protection measures, ensuring access controls, carrying out backups and restorations of contact data, training of employees in the effective use of contact management software, regular review of the communication history, and adjustment of contact strategies); Legal bases: Performance of a contract and pre-contractual requests (Art. 6 para. 1 sentence 1 lit. b) GDPR), legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
- General payment transactions: Procedures required in the execution of payment transactions, the monitoring of bank accounts, and the control of payment flows (e.g., preparation and review of transfers, processing of direct debit transactions, review of account statements, monitoring of incoming and outgoing payments, returned direct debit management, account reconciliation, cash management); Legal bases: Performance of a contract and pre-contractual requests (Art. 6 para. 1 sentence 1 lit. b) GDPR), legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
- Accounting, accounts payable, accounts receivable: Procedures required in the recording, processing, and control of business transactions in the area of accounts payable and accounts receivable (e.g., preparation and review of incoming and outgoing invoices, monitoring and management of open items, execution of payment transactions, handling of the dunning process, account reconciliation in the context of receivables and payables, accounts payable and accounts receivable); Legal bases: Performance of a contract and pre-contractual requests (Art. 6 para. 1 sentence 1 lit. b) GDPR), legal obligation (Art. 6 para. 1 sentence 1 lit. c) GDPR), legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
- Financial accounting and taxes: Procedures required in the recording, management, and control of financially relevant business transactions as well as in the calculation, reporting, and payment of taxes (e.g., allocation and posting of business transactions, preparation of quarterly and annual financial statements, execution of payment transactions, handling of the dunning process, account reconciliation, tax advice, preparation and submission of tax returns, handling of tax matters); Legal bases: Performance of a contract and pre-contractual requests (Art. 6 para. 1 sentence 1 lit. b) GDPR), legal obligation (Art. 6 para. 1 sentence 1 lit. c) GDPR), legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
- Purchasing: Procedures required in the procurement of goods, raw materials, or services (e.g., supplier selection and evaluation, price negotiations, order placement and monitoring, review and control of deliveries, invoice verification, management of orders, inventory management, preparation and maintenance of purchasing guidelines); Legal bases: Performance of a contract and pre-contractual requests (Art. 6 para. 1 sentence 1 lit. b) GDPR), legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
- Sales: Procedures required in the planning, execution, and control of measures for the marketing and sale of products or services (e.g., customer acquisition, preparation and follow-up of quotations, order processing, customer advice and support, sales promotion, product training, sales controlling and analysis, management of sales channels); Legal bases: Performance of a contract and pre-contractual requests (Art. 6 para. 1 sentence 1 lit. b) GDPR), legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
Providers and services used in the course of business
In the course of our business activities, we use, in compliance with the legal requirements, additional services, platforms, interfaces, or plug-ins from third-party providers (in short, “services”). Their use is based on our interests in the proper, lawful, and economical management of our business operations and our internal organization.
- Types of data processed: Inventory data (e.g., full name, residential address, contact information, customer number, etc.); payment data (e.g., bank details, invoices, payment history); contact data (e.g., postal and email addresses or telephone numbers); content data (e.g., textual or pictorial messages and contributions as well as information relating to them, such as details of authorship or the time of creation); contract data (e.g., subject matter of the contract, term, customer category); usage data (e.g., page views and duration of visit, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions); meta, communication, and procedural data (e.g., IP addresses, time stamps, identification numbers, persons involved).
- Data subjects: Service recipients and clients; prospective customers; business and contractual partners.
- Purposes of processing and legitimate interests: Provision of contractual services and fulfillment of contractual obligations; office and organizational procedures; business processes and commercial procedures.
- Retention and erasure: Erasure in accordance with the information provided in the section “General information on data storage and erasure.”
- Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
Further information on processing operations, procedures, and services:
- Diamant Software: Accounting, finance, and controlling; invoicing and human resources; ERP integration; data analysis and reporting; Service provider: Diamant Software GmbH, Stadtring 2, 33647 Bielefeld, Germany; Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Website: https://www.diamant-software.de. Privacy policy: https://www.diamant-software.de/datenschutz/.
Credit assessment
So far we make advance payments or take on comparable economic risks (e.g., when placing an order on account), we reserve the right, in order to safeguard our legitimate interests, to obtain an identity and credit report for the purpose of assessing the credit risk on the basis of mathematical-statistical procedures from service companies specialized in this area (credit agencies).
We process the information received from the credit agencies about the statistical probability of a payment default in the course of an appropriate discretionary decision on the establishment, execution, and termination of the contractual relationship. We reserve the right, in the event of a negative result of the credit assessment, to refuse payment on account or another advance payment.
The decision as to whether we make an advance payment is made, in accordance with the legal requirements, solely on the basis of an automated decision in individual cases, which our software carries out on the basis of the information from the credit agency.
Insofar as we obtain explicit consent from contractual partners, the legal basis for the credit report and the transmission of the customer’s data to the agencies is consent. If no consent is obtained, the credit report is carried out on the basis of our legitimate interests in the reliability of our payment claims.
- Types of data processed: Inventory data (e.g., full name, residential address, contact information, customer number, etc.); payment data (e.g., bank details, invoices, payment history); contact data (e.g., postal and email addresses or telephone numbers); contract data (e.g., subject matter of the contract, term, customer category); credit data (e.g., credit score received, estimated default probability, resulting risk classification, historical payment behavior); usage data (e.g., page views and duration of visit, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions).
- Data subjects: Service recipients and clients; prospective customers; business and contractual partners.
- Purposes of processing and legitimate interests: Assessment of creditworthiness and credit standing.
- Retention and erasure: Erasure in accordance with the information provided in the section “General information on data storage and erasure.”
- Legal bases: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR); legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
- Automated decisions in individual cases: Credit report (decision on the basis of a credit assessment).
Further information on processing operations, procedures, and services:
- Verband der Vereine Creditreform e.V.: Credit agency; Service provider: Verband der Vereine Creditreform e.V., Hammfelddamm 13, 41460 Neuss, Germany; Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Website: https://www.creditreform.de/. Privacy policy: https://www.creditreform.de/datenschutz.
Provision of the online offering and web hosting
We process the data of users in order to be able to provide them with our online services. For this purpose, we process the user’s IP address, which is necessary in order to transmit the content and functions of our online services to the user’s browser or device.
- Types of data processed: Usage data (e.g., page views and duration of visit, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions); meta, communication, and procedural data (e.g., IP addresses, time stamps, identification numbers, persons involved); log data (e.g., log files relating to logins or the retrieval of data or access times); content data (e.g., textual or pictorial messages and contributions as well as information relating to them, such as details of authorship or the time of creation).
- Data subjects: Users (e.g., website visitors, users of online services).
- Purposes of processing and legitimate interests: Provision of our online offering and user-friendliness; information technology infrastructure (operation and provision of information systems and technical devices (computers, servers, etc.)); security measures; provision of contractual services and fulfillment of contractual obligations.
- Retention and erasure: Erasure in accordance with the information provided in the section “General information on data storage and erasure.”
- Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
Further information on processing operations, procedures, and services:
- Provision of the online offering on rented storage space: For the provision of our online offering, we use storage space, computing capacity, and software that we rent or otherwise obtain from a corresponding server provider (also called a “web host”); Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
- Collection of access data and log files: Access to our online offering is logged in the form of so-called “server log files.” The server log files may include the address and name of the web pages and files accessed, the date and time of access, the amount of data transferred, a notification of successful access, the browser type and version, the user’s operating system, the referrer URL (the previously visited page), and, as a rule, IP addresses and the requesting provider. The server log files may be used, on the one hand, for security purposes, e.g., to avoid an overload of the servers (in particular in the case of abusive attacks, so-called DDoS attacks), and, on the other hand, to ensure the utilization of the servers and their stability; Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR). Erasure of data: Log file information is stored for a maximum period of 30 days and then erased or anonymized. Data whose further retention is necessary for evidentiary purposes is exempt from erasure until the respective incident has been finally clarified.
- Email dispatch and hosting: The web hosting services we use also include the sending, receipt, and storage of emails. For these purposes, the addresses of the recipients and senders as well as further information relating to the email dispatch (e.g., the providers involved) and the content of the respective emails are processed. The aforementioned data may also be processed for the purposes of detecting SPAM. We ask you to note that emails on the internet are generally not sent in encrypted form. As a rule, emails are encrypted in transit, but (unless a so-called end-to-end encryption method is used) not on the servers from which they are sent and received. We can therefore accept no responsibility for the transmission path of emails between the sender and receipt on our server; Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
- IONOS: Provision and management of domains (internet addresses), web hosting (storage space for websites), email services, SSL certificates (encryption of data transmission), cloud servers (virtual computing resources), as well as tools for website and server administration; Service provider: IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany; Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Website: https://www.ionos.de; Privacy policy: https://www.ionos.de/datenschutzerklaerung. Data processing agreement: https://www.ionos.de/hilfe/datenschutz/allgemeine-informationen-zur-datenschutz-grundverordnung-dsgvo/vereinbarung-zur-auftragsverarbeitung-avv-mit-ionos-abschliessen/.
Use of Cookies
The term “cookies” refers to functions that store information on users’ devices and read information from them. Cookies may also be used in relation to different concerns, for example for the purposes of the functionality, security, and comfort of online offerings, as well as the creation of analyses of visitor flows. We use cookies in accordance with the legal provisions. To this end, we obtain the prior consent of users where required. Where consent is not necessary, we rely on our legitimate interests. This applies where the storage and reading of information is essential in order to be able to provide expressly requested content and functions. These include, for example, the storage of settings as well as ensuring the functionality and security of our online offering. Consent can be withdrawn at any time. We provide clear information about its scope and which cookies are used.
Information on the data protection legal bases: Whether we process personal data using cookies depends on consent. If consent is present, it serves as the legal basis. Without consent, we rely on our legitimate interests, which are explained above in this section and in the context of the respective services and procedures.
Storage duration: With regard to the storage duration, the following types of cookies are distinguished:
- Temporary cookies (also: session cookies): Temporary cookies are erased at the latest after a user has left an online offering and closed their device (e.g., browser or mobile application).
- Permanent cookies: Permanent cookies remain stored even after the device is closed. For example, the login status can be stored and preferred content can be displayed directly when the user visits a website again. Likewise, the user data collected with the help of cookies can be used for reach measurement. Unless we provide users with explicit information on the type and storage duration of cookies (e.g., in the course of obtaining consent), they should assume that these are permanent and that the storage duration can be up to two years.
General information on withdrawal and objection (opt-out): Users can withdraw the consents they have given at any time and can also object to processing in accordance with the legal requirements, including by means of the privacy settings of their browser.
- Types of data processed: Meta, communication, and procedural data (e.g., IP addresses, time stamps, identification numbers, persons involved).
- Data subjects: Users (e.g., website visitors, users of online services).
- Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); consent (Art. 6 para. 1 sentence 1 lit. a) GDPR).
Further information on processing operations, procedures, and services:
- Processing of cookie data on the basis of consent: We use a consent management solution by means of which the consent of users to the use of cookies, or to the procedures and providers named within the consent management solution, is obtained. This procedure serves the obtaining, logging, management, and withdrawal of consents, in particular with regard to the use of cookies and comparable technologies used to store, read, and process information on users’ devices. In the course of this procedure, users’ consents to the use of cookies and the associated processing of information, including the specific processing operations and providers named in the consent management procedure, are obtained. Users also have the option of managing and withdrawing their consents. The declarations of consent are stored in order to avoid having to request them again and to be able to provide proof of consent in accordance with the legal requirements. Storage takes place on the server side and/or in a cookie (so-called opt-in cookie) or by means of comparable technologies in order to be able to assign the consent to a specific user or their device. Unless specific information on the providers of consent management services is available, the following general information applies: The duration of the storage of the consent is up to two years. In this process, a pseudonymous user identifier is created, which is stored together with the time of consent, the details of the scope of consent (e.g., relevant categories of cookies and/or service providers), and information about the browser, the system, and the device used; Legal bases: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR).
- Complianz: Storage and management of consents (agreement to cookies and data processing), logging of user decisions, display of information on data protection and cookies, enabling users to withdraw or adjust consents; Service provider: Execution on servers and/or computers under our own data protection responsibility; Website: https://complianz.io/; Privacy policy: https://complianz.io/legal/. Further information: An individual user ID, language, and the types of consents and the time of their submission are stored on the server side and in the cookie on the user’s device.
Contact and inquiry management
When contacting us (e.g., by post, contact form, email, telephone, or via social media), as well as in the course of existing user and business relationships, the information of the inquiring persons is processed insofar as this is necessary to respond to the contact inquiries and any requested measures.
- Types of data processed: Contact data (e.g., postal and email addresses or telephone numbers); content data (e.g., textual or pictorial messages and contributions as well as information relating to them, such as details of authorship or the time of creation); meta, communication, and procedural data (e.g., IP addresses, time stamps, identification numbers, persons involved).
- Data subjects: Communication partners.
- Purposes of processing and legitimate interests: Communication; organizational and administrative procedures; feedback (e.g., collecting feedback via online form); provision of our online offering and user-friendliness.
- Retention and erasure: Erasure in accordance with the information provided in the section “General information on data storage and erasure.”
- Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); performance of a contract and pre-contractual requests (Art. 6 para. 1 sentence 1 lit. b) GDPR).
Further information on processing operations, procedures, and services:
- Contact form: When contacting us via our contact form, by email, or by other means of communication, we process the personal data transmitted to us in order to respond to and process the respective request. This generally includes information such as name, contact information, and, where applicable, further information communicated to us and necessary for appropriate processing. We use this data exclusively for the stated purpose of contact and communication; Legal bases: Performance of a contract and pre-contractual requests (Art. 6 para. 1 sentence 1 lit. b) GDPR), legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
Video conferences, online meetings, webinars, and screen sharing
We use platforms and applications of other providers (hereinafter referred to as “conference platforms”) for the purposes of conducting video and audio conferences, webinars, and other types of video and audio meetings (hereinafter collectively referred to as “conference”). When selecting the conference platforms and their services, we observe the legal requirements.
Data processed by conference platforms: In the course of participating in a conference, the conference platforms process the following personal data of the participants. The scope of the processing depends, on the one hand, on which data is required in the course of a specific conference (e.g., provision of access data or real names) and which optional information is provided by the participants. In addition to processing for the purpose of conducting the conference, the participants’ data may also be processed by the conference platforms for security purposes or service optimization. The data processed includes personal data (first name, last name), contact information (email address, telephone number), access data (access codes or passwords), profile pictures, details of professional position/function, the IP address of the internet connection, details of the participants’ devices, their operating system, the browser and its technical and language settings, information on the content of the communication processes, i.e., inputs in chats as well as audio and video data, and the use of other available functions (e.g., surveys). The content of the communications is encrypted to the extent technically provided by the conference providers. If the participants are registered as users with the conference platforms, further data may be processed in accordance with the agreement with the respective conference provider.
Logging and recordings: If text inputs, participation results (e.g., from surveys), or video or audio recordings are logged, this is communicated transparently to the participants in advance, and they are asked for their consent where necessary.
Data protection measures for participants: Please refer to the privacy notices of the conference platforms for details of the processing of your data by them, and select, within the settings of the conference platforms, the security and data protection settings that are optimal for you. Please also ensure, for the duration of a video conference, data protection and privacy protection in the background of your recording (e.g., by informing housemates, locking doors, and using, where technically possible, the function to blur the background). Links to the conference rooms as well as access data must not be passed on to unauthorized third parties.
Information on legal bases: Insofar as we, in addition to the conference platforms, also process the data of users and ask users for their consent to the use of the conference platforms or certain functions (e.g., agreement to a recording of conferences), the legal basis of the processing is this consent. Furthermore, our processing may be necessary for the fulfillment of our contractual obligations (e.g., in participant lists, in the case of processing conversation results, etc.). Otherwise, the data of users is processed on the basis of our legitimate interests in efficient and secure communication with our communication partners.
- Types of data processed: Inventory data (e.g., full name, residential address, contact information, customer number, etc.); contact data (e.g., postal and email addresses or telephone numbers); content data (e.g., textual or pictorial messages and contributions as well as information relating to them, such as details of authorship or the time of creation); usage data (e.g., page views and duration of visit, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions); image and/or video recordings (e.g., photographs or video recordings of a person); sound recordings; log data (e.g., log files relating to logins or the retrieval of data or access times); contract data (e.g., subject matter of the contract, term, customer category); meta, communication, and procedural data (e.g., IP addresses, time stamps, identification numbers, persons involved).
- Data subjects: Communication partners; users (e.g., website visitors, users of online services); depicted persons; service recipients and clients; prospective customers; participants.
- Purposes of processing and legitimate interests: Provision of contractual services and fulfillment of contractual obligations; communication; office and organizational procedures; provision of our online offering and user-friendliness.
- Retention and erasure: Erasure in accordance with the information provided in the section “General information on data storage and erasure.”
- Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
Further information on processing operations, procedures, and services:
- Microsoft Teams: Use for conducting online events and conferences as well as communication with internal and external participants. Voice transmission, direct messages, group communication, and collaboration functions are used; the following are processed: name, business contact data, work profile, participation, and content (audio/video, voice, chat, files, voice transcription) for the purposes of, and in the interest of, increases in efficiency and productivity, cost efficiency, flexibility, mobility, improved communication, IT security, use of a central platform, and the business operations of Microsoft. Audio signals are generally not stored, except when recording is activated. Meeting and conference recordings are stored by default for 90 days, unless a different duration is specified. Chat and file content is stored in accordance with the policies determined by the administrator or user; no automatic erasure is preset. Channels must be renewed every 180 days, otherwise content is erased. In addition, system-generated log, diagnostic, and metadata are processed, and diagnostic data on product stability, security, and improvement is collected; Service provider: Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland; Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA; Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Website: https://www.microsoft.com/de-de/microsoft-teams/; Privacy policy: https://www.microsoft.com/de-de/privacy/privacystatement. Basis for third-country transfers: Data Privacy Framework (DPF), standard contractual clauses (https://www.microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA).
Cloud services
We use software services accessible via the internet and executed on the servers of their providers (so-called “cloud services,” also referred to as “software as a service”) for the storage and management of content (e.g., document storage and management, the exchange of documents, content, and information with certain recipients, or the publication of content and information).
In this context, personal data may be processed and stored on the servers of the providers, insofar as this data is part of communication processes with us or is otherwise processed by us as set out in this privacy policy. This data may include, in particular, master data and contact data of users, data on transactions, contracts, other processes, and their content. The providers of the cloud services also process usage data and metadata, which they use for security purposes and for service optimization.
Insofar as we use the cloud services to provide forms or other documents and content for other users or publicly accessible websites, the providers may store cookies on users’ devices for the purposes of web analytics or to remember users’ settings (e.g., in the case of media control).
- Types of data processed: Inventory data (e.g., full name, residential address, contact information, customer number, etc.); contact data (e.g., postal and email addresses or telephone numbers); content data (e.g., textual or pictorial messages and contributions as well as information relating to them, such as details of authorship or the time of creation); usage data (e.g., page views and duration of visit, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions).
- Data subjects: Prospective customers; communication partners; business and contractual partners.
- Purposes of processing and legitimate interests: Office and organizational procedures; information technology infrastructure (operation and provision of information systems and technical devices (computers, servers, etc.)).
- Retention and erasure: Erasure in accordance with the information provided in the section “General information on data storage and erasure.”
- Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
Further information on processing operations, procedures, and services:
- Microsoft 365 and Microsoft cloud services: Provision of applications, protection of data and IT systems, as well as the use of system-generated log, diagnostic, and metadata for the performance of the contract by Microsoft. The following are processed: contact data (name, email address), content data (files, comments, profiles), software setup and inventory data, device connectivity and configuration data, work interactions (badge swipe), as well as log and metadata. The processing is carried out for the purposes of increases in efficiency and productivity, cost efficiency, flexibility, mobility, improved communication, integration of Microsoft services, IT security, and the business operations of Microsoft. The retention of data is governed by the respective documents and company policies; for Defender (protection of data and IT systems) up to 12 months, for print management 10 days. In addition, diagnostic data on product stability and improvement is collected; Service provider: Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland; Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA; Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Website: https://www.microsoft.com/de-de; Privacy policy: https://privacy.microsoft.com/de-de/privacystatement; Security information: https://www.microsoft.com/de-de/trustcenter; Data processing agreement: https://www.microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA. Basis for third-country transfers: Data Privacy Framework (DPF), standard contractual clauses (https://www.microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA).
Promotional communication via email, post, fax, or telephone
We process personal data for the purposes of promotional communication, which may take place via various channels, such as email, telephone, post, or fax, in accordance with the legal requirements.
The recipients have the right to withdraw consent they have given at any time or to object to promotional communication at any time free of charge via the contact option named above.
After withdrawal or objection, we store the data required to prove the previous authorization for contact or dispatch for up to three years after the end of the year of the withdrawal or objection, on the basis of our legitimate interests. The processing of this data is limited to the purpose of a possible defense against claims. On the basis of the legitimate interest in permanently observing the withdrawal or objection of users, we also store the data required to avoid renewed contact (e.g., depending on the communication channel, the email address, telephone number, name).
- Types of data processed: Inventory data (e.g., full name, residential address, contact information, customer number, etc.); contact data (e.g., postal and email addresses or telephone numbers); content data (e.g., textual or pictorial messages and contributions as well as information relating to them, such as details of authorship or the time of creation).
- Data subjects: Communication partners.
- Purposes of processing and legitimate interests: Direct marketing (e.g., by email or post); marketing; sales promotion.
- Retention and erasure: Erasure in accordance with the information provided in the section “General information on data storage and erasure.”
- Legal bases: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR); legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
Presences in social networks (social media)
We maintain online presences within social networks and, in this context, process user data in order to communicate with the users active there or to offer information about us.
We point out that user data may be processed outside the territory of the European Union in this context. This may give rise to risks for users, because, for example, the enforcement of users’ rights could be made more difficult.
Furthermore, the data of users within social networks is generally processed for market research and advertising purposes. For example, usage profiles can be created on the basis of the usage behavior and the resulting interests of the users. The latter may in turn be used, for example, to place advertisements within and outside the networks that presumably correspond to the interests of the users. For this purpose, cookies are generally stored on the users’ computers, in which the usage behavior and the interests of the users are stored. In addition, data may also be stored in the usage profiles independently of the devices used by the users (in particular if they are members of the respective platforms and logged in there).
For a detailed presentation of the respective forms of processing and the options for objecting (opt-out), we refer to the privacy policies and information of the operators of the respective networks.
Also in the case of requests for access and the assertion of data subjects’ rights, we point out that these can be asserted most effectively with the providers. Only the latter each have access to the user data and can directly take appropriate measures and provide information. Should you nevertheless need assistance, you can contact us.
- Types of data processed: Contact data (e.g., postal and email addresses or telephone numbers); content data (e.g., textual or pictorial messages and contributions as well as information relating to them, such as details of authorship or the time of creation); usage data (e.g., page views and duration of visit, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions).
- Data subjects: Users (e.g., website visitors, users of online services).
- Purposes of processing and legitimate interests: Communication; feedback (e.g., collecting feedback via online form); public relations.
- Retention and erasure: Erasure in accordance with the information provided in the section “General information on data storage and erasure.”
- Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
Further information on processing operations, procedures, and services:
- Instagram: Social network, enables the sharing of photos and videos, commenting on and favoriting contributions, sending messages, subscribing to profiles and pages; Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Website: https://www.instagram.com; Privacy policy: https://privacycenter.instagram.com/policy/. Basis for third-country transfers: Data Privacy Framework (DPF).
- LinkedIn: Social network – We are jointly responsible, together with LinkedIn Ireland Unlimited Company, for the collection (but not the further processing) of data of visitors that is used to create the “Page Insights” (statistics) of our LinkedIn profiles. This data includes information about the types of content that users view or interact with, as well as the actions they take. In addition, details about the devices used are collected, such as IP addresses, operating system, browser type, language settings, and cookie data, as well as information from the user profiles, such as job function, country, industry, seniority level, company size, and employment status. Data protection information on the processing of user data by LinkedIn can be found in LinkedIn’s privacy notices: https://www.linkedin.com/legal/privacy-policy. We have concluded a special agreement with LinkedIn Ireland (“Page Insights Joint Controller Addendum,” https://legal.linkedin.com/pages-joint-controller-addendum), which regulates, in particular, which security measures LinkedIn must observe and in which LinkedIn has agreed to fulfill the rights of data subjects (i.e., users can, for example, direct requests for access or erasure directly to LinkedIn). The rights of users (in particular the right of access, erasure, objection, and complaint to the competent supervisory authority) are not restricted by the agreements with LinkedIn. The joint responsibility is limited to the collection and transmission of the data to LinkedIn Ireland Unlimited Company, a company based in the EU. The further processing of the data is the sole responsibility of LinkedIn Ireland Unlimited Company, in particular with regard to the transmission of the data to the parent company LinkedIn Corporation in the USA; Service provider: LinkedIn Ireland Unlimited Company, Wilton Plaza, Dublin 2, Ireland; Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Website: https://www.linkedin.com; Privacy policy: https://www.linkedin.com/legal/privacy-policy; Basis for third-country transfers: Data Privacy Framework (DPF), standard contractual clauses (https://www.linkedin.com/legal/privacy-policy). Option to object (opt-out): https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.
Plug-ins and embedded functions and content
We integrate functional and content elements into our online offering that are obtained from the servers of their respective providers (hereinafter referred to as “third-party providers”). These may be, for example, graphics, videos, or maps (hereinafter uniformly referred to as “content”).
The integration always requires that the third-party providers of this content process the IP address of the users, since without the IP address they could not send the content to their browser. The IP address is therefore necessary for the display of this content or functions. We endeavor to use only such content whose respective providers use the IP address solely for the delivery of the content. Third-party providers may also use so-called pixel tags (invisible graphics, also referred to as “web beacons”) for statistical or marketing purposes. The “pixel tags” can be used to evaluate information such as visitor traffic on the pages of this website. The pseudonymous information may also be stored in cookies on the user’s device and may contain, among other things, technical information about the browser and the operating system, referring websites, the time of visit, and further details on the use of our online offering, but may also be combined with such information from other sources.
Information on legal bases: Insofar as we ask users for their consent to the use of the third-party providers, the legal basis of the data processing is the permission. Otherwise, the user data is processed on the basis of our legitimate interests (i.e., interest in efficient, economical, and recipient-friendly services). In this context, we would also like to refer you to the information on the use of cookies in this privacy policy.
- Types of data processed: Usage data (e.g., page views and duration of visit, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions); meta, communication, and procedural data (e.g., IP addresses, time stamps, identification numbers, persons involved); contact data (e.g., postal and email addresses or telephone numbers).
- Data subjects: Users (e.g., website visitors, users of online services); communication partners.
- Purposes of processing and legitimate interests: Provision of our online offering and user-friendliness; communication.
- Retention and erasure: Erasure in accordance with the information provided in the section “General information on data storage and erasure.” Storage of cookies of up to 2 years (unless otherwise specified, cookies and similar storage methods may be stored on users’ devices for a period of two years).
- Legal bases: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR); legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
Further information on processing operations, procedures, and services:
- Contact Form 7: Management of contact inquiries and communication; Service provider: Rock Lobster, LLC; Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Website: https://contactform7.com/. Further information: Operation within our own hosting environment.
Application procedure
The application procedure requires applicants to provide us with the data necessary for their assessment and selection. Which information is required results from the job description or the advertisement placed.
In principle, the required information includes personal details such as name, address, a means of contact, and proof of the qualifications necessary for a position. Upon request, we are also happy to inform you which information is required.
Applicants are welcome to send us their applications by email. However, we would like to point out that emails on the internet are generally not sent in encrypted form. Although emails are usually encrypted in transit, this does not take place on the servers from which they are sent and received. We can therefore accept no responsibility for the security of the application on its transmission path between the sender and our server.
For the purposes of applicant search, submission of applications, and selection of applicants, we may, in compliance with the legal requirements, use applicant management or recruitment software and platforms and services of third-party providers.
Applicants are welcome to contact us regarding the method of submitting the application or to send us the application by post.
Processing of special categories of data: Insofar as, in the course of the application procedure, special categories of personal data (Art. 9 para. 1 GDPR, e.g., health data, such as severe disability status or ethnic origin) are requested from applicants or communicated by them, their processing is carried out so that the controller or the data subject can exercise the rights and comply with the obligations arising from employment law and social security and social protection law, in the case of the protection of vital interests of applicants or other persons, or for the purposes of preventive healthcare or occupational medicine, for the assessment of the employee’s working capacity, for medical diagnosis, for the provision of care or treatment in the health or social sector, or for the management of health or social care systems and services.
Erasure of data: In the case of a successful application, the data provided by the applicants may be processed further by us for the purposes of the employment relationship. Otherwise, if the application for a job offer is not successful, the applicants’ data is erased. The applicants’ data is also erased if an application is withdrawn, which the applicants are entitled to do at any time. Subject to a justified withdrawal by the applicants, erasure takes place at the latest after the expiry of a period of six months, so that we can answer any follow-up questions regarding the application and comply with our verification obligations under the provisions on the equal treatment of applicants. Invoices for any reimbursement of travel expenses are archived in accordance with the tax requirements.
Inclusion in an applicant pool: Inclusion in an applicant pool, if offered, is based on consent. Applicants are informed that their consent to inclusion in the talent pool is voluntary, has no influence on the ongoing application procedure, and that they can withdraw their consent at any time for the future.
- Types of data processed: Inventory data (e.g., full name, residential address, contact information, customer number, etc.); contact data (e.g., postal and email addresses or telephone numbers); content data (e.g., textual or pictorial messages and contributions as well as information relating to them, such as details of authorship or the time of creation); applicant data (e.g., personal details, postal and contact addresses, the documents belonging to the application and the information contained therein, such as cover letter, CV, certificates, as well as further information communicated by applicants regarding their person or qualification with regard to a specific position or on a voluntary basis).
- Data subjects: Applicants.
- Purposes of processing and legitimate interests: Application procedure (establishment and any subsequent execution as well as possible subsequent termination of the employment relationship).
- Retention and erasure: Erasure in accordance with the information provided in the section “General information on data storage and erasure.”
- Legal bases: Application procedure as a pre-contractual or contractual relationship (Art. 6 para. 1 sentence 1 lit. b) GDPR); legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
Further information on processing operations, procedures, and services:
- Stepstone: Services in connection with employee recruitment/recruitment (search for employees, communication, application procedure, contract negotiations); Service provider: StepStone Deutschland GmbH, Völklinger Straße 1, 40219 Düsseldorf, Germany; Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Website: https://www.stepstone.de; Privacy policy: https://www.stepstone.de/e-recruiting/rechtliches/datenschutzerklarung/. Data processing agreement: https://www.stepstone.de/e-recruiting/rechtliches/auftragsdatenverarbeitungsvereinbarung/.
Changes und updates
We ask you to inform yourself regularly about the content of our privacy policy. We adapt the privacy policy as soon as changes to the data processing carried out by us make this necessary. We will inform you as soon as the changes require an act of cooperation on your part (e.g., consent) or other individual notification. Insofar as we provide addresses and contact information of companies and organizations in this privacy policy, please note that the addresses may change over time, and we ask you to verify the information before making contact.
Last updated: 1 September 2026
