Skip to main content

Privacy policy

Preamble

With this privacy policy, we would like to inform you about the types of your personal data (hereinafter also referred to in short as „data“) that we process, for what purposes and to what extent, in the context of providing our application.

The terms used are not gender-specific.

Status: 1 September 2026

Table of contents

  • Preamble
  • Controller
  • Contact details of the Data Protection Officer
  • Overview of processing operations
  • Relevant legal bases
  • Security measures
  • Transmission of personal data
  • International data transfers
  • General information on data storage and deletion
  • Rights of data subjects
  • Business services
  • Payment procedures
  • Provision of the online offer and web hosting
  • Use of cookies
  • Processing of data in connection with the application (app)
  • Obtaining applications via app stores
  • Contact and enquiry management
  • Use of AI systems for processing enquiries
  • Video conferences, online meetings, webinars and screen sharing
  • Cloud services
  • Newsletter and electronic notifications
  • Web analytics, monitoring and optimisation
  • Customer reviews and rating procedures
  • Presence on social networks (social media)
  • Plug-ins and embedded functions and content
  • Processing of data in connection with employment relationships
  • Application procedure
  • Amendment and updating
  • Definitions of terms

Controller

signotec GmbH
Am Gierath 20b
40885 Ratingen
Germany

Authorised representatives: Arne Brandes

Email address: info@signotec.de

Telephone: +49 21025357510

Contact details of the Data Protection Officer

signotec GmbH
Data Protection Officer
Am Gierath 20b
40885 Ratingen
Germany

Email: datenschutz@signotec.de

Overview of processing operations

The following overview summarises the types of data processed and the purposes of their processing, and refers to the data subjects concerned.

Types of data processed

  • Master data.
  • Employee data.
  • Payment data.
  • Location data.
  • Contact data.
  • Content data.
  • Contract data.
  • Usage data.
  • Meta, communication and process data.
  • Social data.
  • Applicant data.
  • Image and/or video recordings.
  • Audio recordings.
  • Log data.
  • Performance and conduct data.
  • Working time data.
  • Salary data.

Special categories of data

  • Health data.
  • Religious or philosophical beliefs.
  • Trade union membership.

Categories of data subjects

  • Service recipients and clients.
  • Employees.
  • Prospective customers.
  • Communication partners.
  • Users.
  • Applicants.
  • Business and contractual partners.
  • Persons depicted.

Purposes of processing

  • Provision of contractual services and fulfilment of contractual obligations.
  • Communication.
  • Security measures.
  • Direct marketing.
  • Reach measurement.
  • Tracking.
  • Office and organisational procedures.
  • Target group formation.
  • Organisational and administrative procedures.
  • Application procedure.
  • Feedback.
  • Marketing.
  • Profiles with user-related information.
  • Provision of our online offer and user-friendliness.
  • AI-assisted processing of enquiries.
  • Establishment and performance of employment relationships.
  • Information technology infrastructure.
  • Public relations.
  • Business processes and economic procedures.

Relevant legal bases

Relevant legal bases under the GDPR: Below you will find an overview of the legal bases of the GDPR on the basis of which we process personal data. Please note that in addition to the provisions of the GDPR, national data protection requirements may apply in your or our country of residence or establishment. Should more specific legal bases be relevant in an individual case, we will inform you of these in the privacy policy.

  • Consent (Art. 6 (1) sentence 1 (a) GDPR) – The data subject has given consent to the processing of personal data relating to him or her for one specific purpose or several specific purposes.
  • Performance of a contract and prior requests (Art. 6 (1) sentence 1 (b) GDPR) – Processing is necessary for the performance of a contract to which the data subject is party, or in order to take steps at the request of the data subject prior to entering into a contract.
  • Legal obligation (Art. 6 (1) sentence 1 (c) GDPR) – Processing is necessary for compliance with a legal obligation to which the controller is subject.
  • Legitimate interests (Art. 6 (1) sentence 1 (f) GDPR) – Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, provided that such interests are not overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data.
  • Application procedure as a pre-contractual or contractual relationship (Art. 6 (1) sentence 1 (b) GDPR) – Insofar as special categories of personal data within the meaning of Art. 9 (1) GDPR (e.g. health data such as severe disability status or ethnic origin) are requested from applicants in the course of the application procedure so that the controller or the data subject may exercise rights and comply with obligations arising from employment law and social security and social protection law, such data are processed pursuant to Art. 9 (2) (b) GDPR; where the vital interests of applicants or other persons are to be protected, pursuant to Art. 9 (2) (c) GDPR; or for the purposes of preventive healthcare or occupational medicine, for the assessment of the working capacity of the employee, for medical diagnosis, for the provision of care or treatment in the health or social sector, or for the management of health or social care systems and services, pursuant to Art. 9 (2) (h) GDPR. Where special categories of data are communicated on the basis of voluntary consent, they are processed on the basis of Art. 9 (2) (a) GDPR.
  • Processing of special categories of personal data relating to healthcare, employment and social security (Art. 9 (2) (h) GDPR) – Processing is necessary for the purposes of preventive healthcare or occupational medicine, for the assessment of the working capacity of the employee, for medical diagnosis, for the provision of care or treatment in the health or social sector, or for the management of health or social care systems and services, on the basis of Union law or the law of a Member State or pursuant to a contract with a health professional.

National data protection provisions in Germany: In addition to the data protection provisions of the GDPR, national data protection provisions apply in Germany. These include in particular the Federal Data Protection Act (Bundesdatenschutzgesetz – BDSG). The BDSG contains, in particular, special provisions on the right of access, the right to erasure, the right to object, the processing of special categories of personal data, processing for other purposes and transmission, as well as automated decision-making in individual cases including profiling. Furthermore, the data protection acts of the individual German federal states may apply.

Note on the applicability of the GDPR and the Swiss FADP: This privacy policy serves to provide information both under the Swiss Federal Act on Data Protection (FADP) and under the General Data Protection Regulation (GDPR). For this reason, please note that, on account of the broader territorial application and comprehensibility, the terms of the GDPR are used. In particular, instead of the terms „processing“ of „personal data“, „overriding interest“ and „particularly sensitive personal data“ used in the Swiss FADP, the terms used in the GDPR, namely „processing“ of „personal data“ as well as „legitimate interest“ and „special categories of data“, are used. However, the legal meaning of the terms continues to be determined in accordance with the Swiss FADP within the scope of its application.

Security measures

In accordance with the legal requirements, and taking into account the state of the art, the costs of implementation and the nature, scope, circumstances and purposes of processing, as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, we take appropriate technical and organisational measures to ensure a level of protection appropriate to the risk.

These measures include, in particular, safeguarding the confidentiality, integrity and availability of data by controlling physical and electronic access to the data as well as the access to, input, disclosure, availability and separation of the data. We have furthermore established procedures which ensure the exercise of data subject rights, the deletion of data and responses to threats to the data. In addition, we take the protection of personal data into account as early as the development or selection of hardware, software and procedures, in accordance with the principle of data protection by design and by default.

Securing online connections using TLS/SSL encryption technology (HTTPS): In order to protect the data of users transmitted via our online services against unauthorised access, we use TLS/SSL encryption technology. Secure Sockets Layer (SSL) and Transport Layer Security (TLS) are the cornerstones of secure data transmission on the internet. These technologies encrypt the information transmitted between the website or app and the user’s browser (or between two servers), thereby protecting the data against unauthorised access. TLS, as the further developed and more secure version of SSL, ensures that all data transmissions meet the highest security standards. Where a website is secured by an SSL/TLS certificate, this is signalled by the display of HTTPS in the URL. This serves as an indicator to users that their data are transmitted securely and in encrypted form.

Transmission of personal data

In the course of our processing of personal data, it may occur that these data are transmitted to, or disclosed to, other bodies, companies, legally independent organisational units or persons. Recipients of these data may include, for example, service providers commissioned with IT tasks, or providers of services and content which are integrated into a website. In such cases, we observe the legal requirements and, in particular, conclude appropriate contracts or agreements with the recipients of your data which serve to protect your data.

International data transfers

Data processing in third countries: Insofar as we transfer data to a third country (i.e. outside the European Union (EU) or the European Economic Area (EEA)), or this occurs in the context of using third-party services or the disclosure or transmission of data to other persons, bodies or companies (which is apparent from the postal address of the respective provider or where the privacy policy expressly refers to the transfer of data to third countries), this is always done in accordance with the legal requirements.

For data transfers to the USA, we primarily rely on the Data Privacy Framework (DPF), which was recognised as a secure legal framework by an adequacy decision of the EU Commission of 10 July 2023. In addition, we have concluded Standard Contractual Clauses with the respective providers which comply with the requirements of the EU Commission and set out contractual obligations to protect your data.

This twofold safeguard ensures comprehensive protection of your data: the DPF constitutes the primary level of protection, while the Standard Contractual Clauses serve as additional security. Should changes arise in relation to the DPF, the Standard Contractual Clauses take effect as a reliable fallback option. In this way we ensure that your data always remain adequately protected, even in the event of any political or legal changes. Where a provider is not certified under the DPF, we base the transfer exclusively on Standard Contractual Clauses pursuant to Art. 46 (2) (c) GDPR. We indicate for each individual service which basis applies.

For each individual service provider, we inform you whether they are certified under the DPF and whether Standard Contractual Clauses are in place. Further information on the DPF and a list of certified companies can be found on the website of the US Department of Commerce at https://www.dataprivacyframework.gov/ (in English).

For data transfers to other third countries, corresponding safeguards apply, in particular Standard Contractual Clauses, express consent or transfers required by law. Information on third-country transfers and applicable adequacy decisions can be found in the information provided by the EU Commission: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection_en.

General information on data storage and deletion

We delete personal data that we process in accordance with the statutory provisions as soon as the underlying consents are withdrawn or no further legal bases for the processing exist. This applies to cases in which the original purpose of processing ceases to apply or the data are no longer required. Exceptions to this rule exist where statutory obligations or overriding interests require longer retention or archiving of the data.

In particular, data which must be retained for commercial or tax law reasons, or the storage of which is necessary for the pursuit of legal claims or the protection of the rights of other natural or legal persons, must be archived accordingly.

Our privacy notices contain additional information on the retention and deletion of data which applies specifically to certain processing operations.

Where several statements are made regarding the retention period or deletion deadlines for a particular item of data, the longest period shall always be decisive. Data which are no longer retained for the originally intended purpose but on account of statutory requirements or other reasons are processed by us exclusively for the reasons which justify their retention.

Retention and deletion of data: The following general periods apply to retention and archiving under German law:

  • 10 years – Retention period for books and records, annual financial statements, inventories, management reports, opening balance sheets, as well as the working instructions and other organisational documents required for their understanding (Section 147 (1) no. 1 in conjunction with (3) AO, Section 14b (1) UStG, Section 257 (1) no. 1 in conjunction with (4) HGB).
  • 8 years – Accounting vouchers, such as invoices and expense receipts (Section 147 (1) nos. 4 and 4a in conjunction with (3) sentence 1 AO and Section 257 (1) no. 4 in conjunction with (4) HGB).
  • 6 years – Other business documents: commercial or business letters received, copies of commercial or business letters sent, other documents insofar as they are relevant for taxation, e.g. hourly wage slips, cost accounting sheets, calculation documents, price labelling, but also payroll accounting documents insofar as they are not already accounting vouchers, and till rolls (Section 147 (1) nos. 2, 3, 5 in conjunction with (3) AO, Section 257 (1) nos. 2 and 3 in conjunction with (4) HGB).
  • 3 years – Data which are required in order to take into account potential warranty and damages claims or similar contractual claims and rights, as well as to process related enquiries, based on past business experience and customary industry practice, are stored for the duration of the regular statutory limitation period of three years (Sections 195, 199 BGB).

Commencement of the period at the end of the year: Where a period does not expressly commence on a specific date and amounts to at least one year, it automatically starts at the end of the calendar year in which the event triggering the period occurred. In the case of ongoing contractual relationships in the context of which data are stored, the event triggering the period is the point at which the termination or other ending of the legal relationship takes effect.

Rights of data subjects

Rights of data subjects under the GDPR: As a data subject, you are entitled to various rights under the GDPR, which arise in particular from Art. 15 to 21 GDPR:

  • Right to object: You have the right to object, on grounds relating to your particular situation, at any time to the processing of personal data concerning you which is carried out on the basis of Art. 6 (1) (e) or (f) GDPR; this also applies to profiling based on those provisions. Where personal data concerning you are processed for direct marketing purposes, you have the right to object at any time to the processing of personal data concerning you for the purposes of such marketing; this also applies to profiling insofar as it is related to such direct marketing.
  • Right to withdraw consent: You have the right to withdraw consent given at any time.
  • Right of access: You have the right to request confirmation as to whether data concerning you are being processed and to obtain access to those data as well as further information and a copy of the data in accordance with the legal requirements.
  • Right to rectification: You have the right, in accordance with the legal requirements, to request the completion of data concerning you or the rectification of inaccurate data concerning you.
  • Right to erasure and restriction of processing: You have the right, in accordance with the legal requirements, to request that data concerning you be erased without delay, or alternatively to request a restriction of the processing of the data in accordance with the legal requirements.
  • Right to data portability: You have the right to receive data concerning you which you have provided to us, in accordance with the legal requirements, in a structured, commonly used and machine-readable format, or to request its transmission to another controller.
  • Complaint to a supervisory authority: In accordance with the legal requirements and without prejudice to any other administrative or judicial remedy, you also have the right to lodge a complaint with a data protection supervisory authority, in particular a supervisory authority in the Member State of your habitual residence, the supervisory authority of your place of work or of the place of the alleged infringement, if you consider that the processing of personal data concerning you infringes the GDPR.

Business services

We process personal data of our contractual and business partners, such as customers, clients, prospective customers, suppliers and other cooperation partners (collectively „contractual partners“), for the initiation, performance and settlement of contractual relationships and comparable legal relationships. This also includes pre-contractual measures taken upon request, as well as communication in connection with the respective contractual relationship.

The processing serves in particular the fulfilment of our primary and ancillary contractual obligations. These include the provision of the agreed services, any update and information obligations, the handling of warranty claims and other performance issues, the processing of withdrawals, terminations of continuing obligations, reversals and refunds, as well as the handling of other contract-related declarations and enquiries. This covers both one-off contracts and ongoing contractual relationships.

In particular, we process master data such as name, address and, where applicable, company, contact data such as email address and telephone number, contract and performance data such as subject matter of the contract, contract term, order or case number, usage and performance data, payment and billing data, as well as communication content and histories. Where necessary, we also process data disclosed or transmitted to us in the course of carrying out an order.

In addition, we process the data in order to safeguard our rights and to comply with legal obligations. This includes in particular commercial and tax law retention obligations, documentation obligations and, where applicable, obligations of proof and accountability. Processing furthermore takes place on the basis of our legitimate interests in proper business management, internal administration, risk management and IT security, as well as in protecting our business operations and our contractual partners against misuse, threats to data, trade secrets and other legally protected interests. This may also include the involvement of external service providers such as IT and telecommunications providers, transport and logistics companies, payment service providers, banks, tax and legal advisers or other vicarious agents, insofar as this is necessary for the performance of the contract or for compliance with legal obligations.

Personal data are disclosed to third parties exclusively insofar as this is necessary for the performance of the contract, for the implementation of pre-contractual measures, for safeguarding legitimate interests or for compliance with legal obligations. We provide separate information within this privacy policy on any processing going beyond this, in particular for marketing purposes.

We inform contractual partners which data are required in the individual case in the course of data collection, for example in online forms by way of corresponding marking, or in personal contact.

The data are deleted as soon as they are no longer required for the aforementioned purposes and no statutory retention obligations prevent deletion. Statutory retention periods, in particular under commercial and tax law, may require longer storage. Data transmitted in the course of a specific order are deleted by us upon completion of the order and expiry of any retention periods, provided that no further statutory or contractual storage obligations exist.

The legal basis for the processing is Art. 6 (1) (b) GDPR for the implementation of pre-contractual measures and the performance of the respective contractual relationship, as well as Art. 6 (1) (c) GDPR for compliance with legal obligations. Insofar as the processing is based on legitimate interests, it takes place on the basis of Art. 6 (1) (f) GDPR. Where processing is based on Art. 6 (1) (f) GDPR, it serves to safeguard our legitimate interests in a proper and efficient business organisation, the internal administration and documentation of business transactions, the enforcement and defence of legal claims, ensuring IT and data security, preventing misuse and fraud, as well as the economic management and further development of our business operations. These interests consist in particular in ensuring secure and legally compliant business operations and in maintaining our entrepreneurial capacity to act.

  • Types of data processed: Master data (e.g. full name, residential address, contact information, customer number, etc.); Payment data (e.g. bank details, invoices, payment history); Contact data (e.g. postal and email addresses or telephone numbers); Contract data (e.g. subject matter of the contract, term, customer category); Usage data (e.g. page views and time spent, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions). Meta, communication and process data (e.g. IP addresses, timestamps, identification numbers, persons involved).
  • Data subjects: Service recipients and clients; Prospective customers. Business and contractual partners.
  • Purposes of processing and legitimate interests: Provision of contractual services and fulfilment of contractual obligations; Security measures; Communication; Office and organisational procedures; Organisational and administrative procedures. Business processes and economic procedures.
  • Retention and deletion: Deletion in accordance with the information provided in the section „General information on data storage and deletion“.
  • Legal bases: Performance of a contract and prior requests (Art. 6 (1) sentence 1 (b) GDPR); Legal obligation (Art. 6 (1) sentence 1 (c) GDPR). Legitimate interests (Art. 6 (1) sentence 1 (f) GDPR).

Further information on processing operations, procedures and services:

  • Online shop, order forms, e-commerce and performance of services: We process the data of our customers in order to enable them to select, purchase or order the chosen products, goods and associated services, as well as to pay for and receive or have them delivered or performed. Where necessary for carrying out an order, we engage service providers, in particular postal, freight forwarding and shipping companies, in order to carry out the delivery or performance for our customers. For the handling of payment transactions, we use the services of banks and payment service providers. The required information is marked as such in the course of the order or comparable purchase process and comprises the information required for delivery or provision and billing, as well as contact information in order to be able to make any enquiries; Legal bases: Performance of a contract and prior requests (Art. 6 (1) sentence 1 (b) GDPR).
  • Consulting: We process the data of our clients as well as prospective clients and other principals or contractual partners (uniformly referred to as „clients“) in order to be able to provide our services to them. The procedures forming part of and serving the purposes of consulting include: contacting and communicating with clients, carrying out needs and requirements analyses, planning and implementing consulting projects, documenting project progress and results, recording and managing client-specific information and data, scheduling and organisation, providing consulting resources and materials, billing and payment management, follow-up work on consulting projects, and quality assurance and feedback processes. The data processed, the nature, scope, purpose and necessity of their processing are determined by the underlying contractual and client relationship. Insofar as it is necessary for the performance of our contract, for the protection of vital interests or required by law, or where the consent of the clients is available, we disclose or transmit client data, in compliance with professional law requirements, to third parties or agents, such as public authorities, subcontractors or providers of IT, office or comparable services; Legal bases: Performance of a contract and prior requests (Art. 6 (1) sentence 1 (b) GDPR).
  • IT services: We process the data of our customers and clients in order to enable them to plan and implement IT solutions and related services, and to receive support for them. The required information is marked as such in the course of the order, project or comparable conclusion of contract and comprises the information required for the provision of services and billing, as well as contact information in order to be able to make any enquiries. Insofar as we obtain access to information relating to end customers, employees or other persons, we process this in accordance with the statutory and contractual requirements.
    The processing operations include, among other things, project administration and documentation, covering all phases from the initial requirements analysis to the completion of the project. This includes the creation and management of project schedules, budgets and resource allocations. The data processing also supports change management, in which changes in the project workflow are documented and tracked in order to ensure compliance and transparency. A further process is customer relationship management (CRM), which comprises the recording and analysis of customer interactions and feedback in order to improve the quality of services and to address individual customer needs efficiently. In addition, the processing operation comprises technical support and troubleshooting, which includes the recording and handling of support requests, error rectification and regular maintenance. Furthermore, reporting and performance analysis are carried out, whereby performance indicators are recorded and evaluated in order to assess the effectiveness of the IT solutions provided and to optimise them on an ongoing basis. All of these processes are designed to ensure a high level of customer satisfaction and compliance with all relevant requirements; Legal bases: Performance of a contract and prior requests (Art. 6 (1) sentence 1 (b) GDPR), Legal obligation (Art. 6 (1) sentence 1 (c) GDPR), Legitimate interests (Art. 6 (1) sentence 1 (f) GDPR).
  • Provision of software and platform services: We process the data of our users, registered users and any trial users (hereinafter uniformly referred to as „users“) in order to be able to provide our contractual services to them, as well as on the basis of legitimate interests in order to be able to ensure the security of our offering and to develop it further. The required information is marked as such in the course of the order or comparable conclusion of contract and comprises the information required for the provision of services and billing, as well as contact information in order to be able to make any enquiries; Legal bases: Performance of a contract and prior requests (Art. 6 (1) sentence 1 (b) GDPR).

Payment procedures

Within the framework of contractual and other legal relationships, on account of legal obligations or otherwise on the basis of our legitimate interests, we offer data subjects efficient and secure payment options and, in addition to banks and credit institutions, engage further service providers for this purpose (collectively „payment service providers“). Payment transactions are carried out in accordance with the state of the art exclusively via encrypted connections, so that the data entered are protected against unauthorised access during transmission.

The data processed by the payment service providers include master data, such as the name and address, bank data, such as account numbers or credit card numbers, passwords, TANs and checksums, as well as contract, total and recipient-related information. This information is required in order to carry out the transactions. However, the data entered are processed and stored only by the payment service providers. This means that we do not receive any account- or credit card-related information, but only information confirming or declining the payment. In certain circumstances, the data are transmitted by the payment service providers to credit agencies. The purpose of this transmission is identity and creditworthiness checking. In this respect, we refer to the terms and conditions and the privacy notices of the payment service providers.

The terms and conditions and the privacy notices of the respective payment service providers apply to payment transactions and can be accessed within the respective websites or transaction applications. We also refer to these for further information and for the assertion of rights of withdrawal, access and other data subject rights.

  • Types of data processed: Master data (e.g. full name, residential address, contact information, customer number, etc.); Payment data (e.g. bank details, invoices, payment history); Contract data (e.g. subject matter of the contract, term, customer category); Usage data (e.g. page views and time spent, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions). Meta, communication and process data (e.g. IP addresses, timestamps, identification numbers, persons involved).
  • Data subjects: Service recipients and clients; Business and contractual partners. Prospective customers.
  • Purposes of processing and legitimate interests: Provision of contractual services and fulfilment of contractual obligations. Business processes and economic procedures.
  • Retention and deletion: Deletion in accordance with the information provided in the section „General information on data storage and deletion“.
  • Legal bases: Performance of a contract and prior requests (Art. 6 (1) sentence 1 (b) GDPR). Legitimate interests (Art. 6 (1) sentence 1 (f) GDPR).

Further information on processing operations, procedures and services:

  • Mollie: Payment services (technical integration of online payment methods); Service provider: Mollie B.V., Keizersgracht 126, 1015 CW Amsterdam, Netherlands; Legal bases: Performance of a contract and prior requests (Art. 6 (1) sentence 1 (b) GDPR); Website: https://www.mollie.com/en. Privacy policy: https://www.mollie.com/en/privacy.
  • PayPal: Payment services (technical integration of online payment methods) (e.g. PayPal, PayPal Plus, Braintree); Service provider: PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg; Legal bases: Performance of a contract and prior requests (Art. 6 (1) sentence 1 (b) GDPR); Website: https://www.paypal.com. Privacy policy: https://www.paypal.com/uk/legalhub/paypal/privacy-full.

Provision of the online offer and web hosting

We process the data of users in order to be able to provide our online services to them. For this purpose, we process the user’s IP address, which is necessary in order to transmit the content and functions of our online services to the user’s browser or device.

  • Types of data processed: Usage data (e.g. page views and time spent, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions); Meta, communication and process data (e.g. IP addresses, timestamps, identification numbers, persons involved). Log data (e.g. log files concerning logins or the retrieval of data or access times).
  • Data subjects: Users (e.g. website visitors, users of online services).
  • Purposes of processing and legitimate interests: Provision of our online offer and user-friendliness; Information technology infrastructure (operation and provision of information systems and technical devices (computers, servers, etc.)). Security measures.
  • Retention and deletion: Deletion in accordance with the information provided in the section „General information on data storage and deletion“.
  • Legal bases: Legitimate interests (Art. 6 (1) sentence 1 (f) GDPR).

Further information on processing operations, procedures and services:

  • Provision of the online offer on rented storage space: For the provision of our online offer, we use storage space, computing capacity and software which we rent or otherwise obtain from a corresponding server provider (also referred to as a „web host“); Legal bases: Legitimate interests (Art. 6 (1) sentence 1 (f) GDPR).
  • Collection of access data and log files: Access to our online offer is logged in the form of so-called „server log files“. Server log files may include the address and name of the web pages and files accessed, the date and time of access, the volume of data transferred, notification of successful access, browser type and version, the user’s operating system, referrer URL (the previously visited page) and, as a rule, IP addresses and the requesting provider. Server log files may be used, on the one hand, for security purposes, e.g. to avoid overloading the servers (in particular in the case of abusive attacks, so-called DDoS attacks), and, on the other hand, to ensure the utilisation of the servers and their stability; Legal bases: Legitimate interests (Art. 6 (1) sentence 1 (f) GDPR). Deletion of data: Log file information is stored for a maximum period of 30 days and thereafter deleted or anonymised. Data whose further retention is required for evidentiary purposes are exempt from deletion until the respective incident has been finally clarified.
  • Hetzner: Services in the field of the provision of information technology infrastructure and related services (e.g. storage space and/or computing capacity); Service provider: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany; Legal bases: Legitimate interests (Art. 6 (1) sentence 1 (f) GDPR); Website: https://www.hetzner.com; Privacy policy: https://www.hetzner.com/rechtliches/datenschutz. Data processing agreement: https://docs.hetzner.com/general/general-terms-and-conditions/data-privacy-faq/.
  • Netlify: Creation, management and hosting of websites, online forms and other web elements; Service provider: Netlify, Inc, 2343 3rd Street, Suite 296, San Francisco, California 94107, USA; Legal bases: Legitimate interests (Art. 6 (1) sentence 1 (f) GDPR); Website: https://www.netlify.com/; Privacy policy: https://www.netlify.com/privacy/; Data processing agreement: https://www.netlify.com/gdpr-ccpa/. Basis for third-country transfers: Standard Contractual Clauses (https://www.netlify.com/gdpr-ccpa/).

Use of cookies

The term „cookies“ refers to functions which store information on users‘ devices and read information from them. Cookies may furthermore be used in relation to various concerns, for example for the purposes of the functionality, security and convenience of online offerings, as well as the creation of analyses of visitor flows. We use cookies in accordance with the statutory provisions. To this end, we obtain users‘ consent in advance where required. Where consent is not necessary, we rely on our legitimate interests. This applies where the storage and reading of information is essential in order to be able to provide expressly requested content and functions. This includes, for example, the storage of settings and ensuring the functionality and security of our online offer. Consent may be withdrawn at any time. We provide clear information on its scope and on which cookies are used.

Information on legal bases under data protection law: Whether we process personal data with the aid of cookies depends on consent. Where consent has been given, it serves as the legal basis. Without consent, we rely on our legitimate interests, which are explained above in this section and in the context of the respective services and procedures.

Storage period: With regard to the storage period, the following types of cookies are distinguished:

  • Temporary cookies (also: session cookies): Temporary cookies are deleted at the latest after a user has left an online offer and closed their device (e.g. browser or mobile application).
  • Permanent cookies: Permanent cookies remain stored even after the device has been closed. In this way, for example, the login status can be stored and preferred content displayed directly when the user visits a website again. Likewise, the user data collected with the aid of cookies may be used for reach measurement. Insofar as we do not provide users with explicit information on the type and storage period of cookies (e.g. in the course of obtaining consent), users should assume that these are permanent and that the storage period may be up to two years.

General information on withdrawal and objection (opt-out): Users may withdraw the consent they have given at any time and may also object to the processing in accordance with the statutory requirements, including by means of the privacy settings of their browser.

  • Types of data processed: Meta, communication and process data (e.g. IP addresses, timestamps, identification numbers, persons involved).
  • Data subjects: Users (e.g. website visitors, users of online services).
  • Legal bases: Legitimate interests (Art. 6 (1) sentence 1 (f) GDPR). Consent (Art. 6 (1) sentence 1 (a) GDPR).

Further information on processing operations, procedures and services:

  • Processing of cookie data on the basis of consent: We use a consent management solution by means of which users‘ consent to the use of cookies, or to the procedures and providers named within the consent management solution, is obtained. This procedure serves to obtain, log, manage and withdraw consent, in particular in relation to the use of cookies and comparable technologies which are used to store, read and process information on users‘ devices. Within the framework of this procedure, users‘ consent is obtained for the use of cookies and the associated processing of information, including the specific processing operations and providers named in the consent management procedure. Users also have the possibility of managing and withdrawing their consent. The declarations of consent are stored in order to avoid repeated requests and to be able to provide evidence of consent in accordance with the statutory requirements. Storage takes place on the server side and/or in a cookie (a so-called opt-in cookie) or by means of comparable technologies, in order to be able to attribute the consent to a specific user or their device. Insofar as no specific information on the providers of consent management services is available, the following general information applies: the storage period for the consent is up to two years. A pseudonymous user identifier is created and stored together with the time of consent, the information on the scope of the consent (e.g. relevant categories of cookies and/or service providers) as well as information on the browser, the system and the device used; Legal bases: Consent (Art. 6 (1) sentence 1 (a) GDPR).
  • Cookiebot: Storage and management of consent (agreement to cookies and data processing), logging of user decisions, display of notices on data protection and cookies, enabling users to withdraw or adjust their consent; Service provider: Usercentrics A/S, Havnegade 39, 1058 Copenhagen, Denmark; Website: https://www.cookiebot.com/en; Privacy policy: https://www.cookiebot.com/en/privacy-policy/; Data processing agreement: Provided by the service provider; Further information: Stored data (on the service provider’s server): the user’s IP number in anonymised form (the last three digits are set to 0), date and time of consent, browser details, the URL from which the consent was sent, an anonymous, random and encrypted key value, the user’s consent status.

Processing of data in connection with the signotec applications (apps)

We process the data of the users of our applications insofar as this is necessary in order to provide users with the respective application and its functionalities, to monitor its security and to develop it further. We may also contact users, in compliance with the statutory requirements, insofar as communication is necessary for the purposes of administering or using the application. In all other respects, with regard to the processing of users‘ data, we refer to the privacy notices in this privacy policy.

Legal bases: The processing of data which is necessary for the provision of the functionalities of the application serves the fulfilment of contractual obligations. This also applies where the provision of the functions requires a permission from the user (e.g. release of device functions). Insofar as the processing of data is not necessary for the provision of the functionalities of the application but serves the security of the application or our business interests (e.g. collection of data for the purposes of optimising the application or for security purposes), it takes place on the basis of our legitimate interests. Insofar as users are expressly asked for their consent to the processing of their data, the processing of the data covered by the consent takes place on the basis of that consent.

  • Types of data processed: Master data (e.g. full name, residential address, contact information, customer number, etc.); Usage data (e.g. page views and time spent, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions); Meta, communication and process data (e.g. IP addresses, timestamps, identification numbers, persons involved); Payment data (e.g. bank details, invoices, payment history); Contract data (e.g. subject matter of the contract, term, customer category); Image and/or video recordings (e.g. photographs or video recordings of a person). Location data (information on the geographical position of a device or a person).
  • Data subjects: Users (e.g. website visitors, users of online services).
  • Purposes of processing and legitimate interests: Provision of contractual services and fulfilment of contractual obligations; Security measures. Provision of our online offer and user-friendliness.
  • Retention and deletion: Deletion in accordance with the information provided in the section „General information on data storage and deletion“.
  • Legal bases: Performance of a contract and prior requests (Art. 6 (1) sentence 1 (b) GDPR). Legitimate interests (Art. 6 (1) sentence 1 (f) GDPR).

Further information on processing operations, procedures and services:

  • Commercial use: We process the data of the users of our application, registered users and any trial users (hereinafter uniformly referred to as „users“) in order to be able to provide our contractual services to them, as well as on the basis of legitimate interests in order to be able to ensure the security of our application and to develop it further. The required information is marked as such in the course of the usage, order or comparable conclusion of contract and may comprise the information required for the provision of services and any billing, as well as contact information in order to be able to make any enquiries; Legal bases: Performance of a contract and prior requests (Art. 6 (1) sentence 1 (b) GDPR).
  • Storage of a universally unique identifier (UUID): For the purposes of analysing the use and functionality of the application and of storing users‘ settings, the application stores a so-called universally unique identifier (UUID). This identifier is generated upon installation of this application (but is not linked to the device and is therefore not a device identifier in this sense), remains stored between the launch of the application and its updates, and is deleted when users remove the application from their device.
  • Device permissions for access to functions and data: The use of our application or its functionalities may require permissions from users for access to certain functions of the devices used or to the data stored on the devices or accessible with the aid of the devices. By default, these permissions must be granted by users and may be withdrawn at any time in the settings of the respective devices. The precise procedure for controlling app permissions may depend on the user’s device and software. Users may contact us if they require clarification. We point out that the refusal or withdrawal of the respective permissions may affect the functionality of our application.
  • Access to the camera and to stored recordings: In the course of using our application, image and/or video recordings (which also include audio recordings) of users (and of other persons captured by the recordings) are processed by means of access to the camera functions or to stored recordings. Access to the camera functions or stored recordings requires a permission from users which may be withdrawn at any time. The processing of the image and/or video recordings serves in each case only the provision of the respective functionality of our application, in accordance with its description to users or its typical and foreseeable mode of operation.
  • Processing of location data: In the course of using our application, the location data collected by the device used or otherwise entered by users are processed. The use of location data requires a permission from users which may be withdrawn at any time. The use of the location data serves in each case only the provision of the respective functionality of our application, in accordance with its description to users or its typical and foreseeable mode of operation.
  • No location history and no movement profiles: The location data are used only on a case-by-case basis and are not processed to create a location history or a movement profile of the devices used or their users.
  • Product activation: In order to ensure the proper use and licensing of our software, in the case of products with online licensing a device ID and licence information are automatically transmitted to us at regular intervals – as a rule every 24 hours, but at least once every 60 days. These data are processed exclusively for the purpose of licence validation; Legal bases: Performance of a contract and prior requests (Art. 6 (1) sentence 1 (b) GDPR), Legitimate interests (Art. 6 (1) sentence 1 (f) GDPR) in ensuring use of the software in accordance with the contract and in protection against unauthorised use. Deletion of data: Deletion in accordance with the information provided in the section „General information on data storage and deletion“.
  • Software as a service: We host SaaS and licensing services within Germany. No transfer of data outside the EU takes place in connection with the operation of these services unless this is expressly indicated and permitted under data protection law (e.g. by EU Standard Contractual Clauses). One such indicated exception concerns the use of AI-assisted systems when processing enquiries; in this respect we refer to the section „Use of AI systems for processing enquiries“. The hosting environment used and the respective sub-processors engaged are determined contractually and depend on the individually agreed scope of services; the corresponding details form part of the respective service agreement and of the data processing agreement pursuant to Art. 28 GDPR. Further information can be found in the respective service agreements and terms of use.
  • Data security: We implement technical and organisational measures (TOMs) in order to protect your data against manipulation, loss, destruction or unauthorised access. These include encrypted connections, access controls and regular security updates. The current TOMs are available on request at info@signotec.de.

Obtaining applications via app stores

Our application is obtained via special online platforms operated by other service providers (so-called „app stores“). In this context, the privacy notices of the respective app stores apply in addition to our privacy notices. This applies in particular with regard to the procedures used on the platforms for reach measurement and interest-based marketing, as well as any charges.

  • Types of data processed: Master data (e.g. full name, residential address, contact information, customer number, etc.); Payment data (e.g. bank details, invoices, payment history); Contact data (e.g. postal and email addresses or telephone numbers); Contract data (e.g. subject matter of the contract, term, customer category); Usage data (e.g. page views and time spent, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions). Meta, communication and process data (e.g. IP addresses, timestamps, identification numbers, persons involved).
  • Data subjects: Service recipients and clients. Users (e.g. website visitors, users of online services).
  • Purposes of processing and legitimate interests: Provision of contractual services and fulfilment of contractual obligations. Provision of our online offer and user-friendliness.
  • Retention and deletion: Deletion in accordance with the information provided in the section „General information on data storage and deletion“.
  • Legal bases: Legitimate interests (Art. 6 (1) sentence 1 (f) GDPR).

Further information on processing operations, procedures and services:

Contact and enquiry management

When contacting us (e.g. by post, contact form, email, telephone or via social media), as well as within the framework of existing user and business relationships, the information provided by the enquiring persons is processed insofar as this is necessary in order to respond to the contact enquiries and any requested measures.

  • Types of data processed: Contact data (e.g. postal and email addresses or telephone numbers); Content data (e.g. textual or pictorial messages and contributions as well as the information relating to them, such as details of authorship or the time of creation); Meta, communication and process data (e.g. IP addresses, timestamps, identification numbers, persons involved). Usage data (e.g. page views and time spent, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions).
  • Data subjects: Communication partners; Service recipients and clients; Prospective customers. Business and contractual partners.
  • Purposes of processing and legitimate interests: Communication; Organisational and administrative procedures; Feedback (e.g. collecting feedback via an online form); Provision of our online offer and user-friendliness. Office and organisational procedures.
  • Retention and deletion: Deletion in accordance with the information provided in the section „General information on data storage and deletion“.
  • Legal bases: Legitimate interests (Art. 6 (1) sentence 1 (f) GDPR). Performance of a contract and prior requests (Art. 6 (1) sentence 1 (b) GDPR).

Further information on processing operations, procedures and services:

  • Contact form: When you contact us via our contact form, by email or by other means of communication, we process the personal data transmitted to us in order to answer and handle the respective matter. This generally includes information such as name, contact details and, where applicable, further information communicated to us and required for appropriate handling. We use these data exclusively for the stated purpose of contact and communication; Legal bases: Performance of a contract and prior requests (Art. 6 (1) sentence 1 (b) GDPR), Legitimate interests (Art. 6 (1) sentence 1 (f) GDPR).
  • Freshdesk: Management of contact enquiries and communication. The system also offers AI-assisted functions, for example for the categorisation and prioritisation of enquiries, the summarisation of cases and the pre-drafting of responses. Insofar as we activate these functions, the data contained in the respective case are processed for this purpose; the review of, and responsibility for, the response addressed to you remains in every case with a responsible person. The information in the section „Use of AI systems for processing enquiries“ applies in addition; Service provider: Freshworks, Inc., 2950 S. Delaware Street, Suite 201, San Mateo, CA 94403, USA; Legal bases: Performance of a contract and prior requests (Art. 6 (1) sentence 1 (b) GDPR), Legitimate interests (Art. 6 (1) sentence 1 (f) GDPR); Website: https://www.freshworks.com; Privacy policy: https://www.freshworks.com/privacy/; Data processing agreement: https://www.freshworks.com/data-processing-addendum/. Basis for third-country transfers: Standard Contractual Clauses (https://www.freshworks.com/data-processing-addendum/).
  • Microsoft Bookings: Online appointment scheduling and appointment management; Service provider: Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland; Legal bases: Legitimate interests (Art. 6 (1) sentence 1 (f) GDPR); Website: https://www.microsoft.com/en/microsoft-365/business/scheduling-and-booking-app; Privacy policy: https://privacy.microsoft.com/en-us/privacystatement. Data processing agreement: https://www.microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA.

Use of AI systems for processing enquiries

We use AI-assisted systems to process support, sales and other enquiries. These systems assist us in particular with analysing and narrowing down technical faults, evaluating log and diagnostic data, summarising cases and communication histories, analysing needs and requirements, and pre-drafting responses and quotation documents. In this context, personal data transmitted to us in connection with the respective enquiry may be processed.

Insofar as personal data of third parties are transmitted to us in connection with an enquiry – for example data of employees or end customers of our customers, such as in attached documents, log files or screen recordings – we process these data as controller for the aforementioned purposes. It is generally not possible for us to inform these persons directly; we therefore provide information via this privacy policy (Art. 14 (5) GDPR). We ask our customers to transmit to us only such data as are necessary for processing the matter, and to anonymise or remove personal data of third parties beforehand where possible.

The results produced by the AI systems serve exclusively as a working basis. Every response addressed to you and every decision is reviewed by, and remains the responsibility of, a responsible person. A decision based solely on automated processing which produces legal effects or similarly significantly affects you within the meaning of Art. 22 GDPR does not take place. We have adopted internal guidelines limiting the scope of data that may be entered into AI systems; special categories of personal data pursuant to Art. 9 GDPR are not entered.

Data processing agreements pursuant to Art. 28 GDPR are in place with the providers used. Use of the transmitted data to train the providers‘ models is contractually excluded. Part of the processing takes place on infrastructure in the United States; the transfer is based on Standard Contractual Clauses pursuant to Art. 46 (2) (c) GDPR.

  • Types of data processed: Contact data (e.g. postal and email addresses or telephone numbers); Content data (e.g. contents of enquiries, transmitted documents, log and diagnostic data, screen recordings); Contract data (e.g. subject matter of the contract, term, customer category). Meta, communication and process data (e.g. IP addresses, timestamps, identification numbers, persons involved).
  • Data subjects: Communication partners; Service recipients and clients; Prospective customers; Business and contractual partners. Users (e.g. website visitors, users of online services).
  • Purposes of processing and legitimate interests: AI-assisted processing of enquiries; Communication; Provision of contractual services and fulfilment of contractual obligations; Office and organisational procedures; Security measures. Business processes and economic procedures.
  • Retention and deletion: Deletion in accordance with the information provided in the section „General information on data storage and deletion“.
  • Legal bases: Performance of a contract and prior requests (Art. 6 (1) sentence 1 (b) GDPR). Legitimate interests (Art. 6 (1) sentence 1 (f) GDPR) in the efficient, prompt and high-quality processing of enquiries and in ensuring reliable product support.

Further information on processing operations, procedures and services: In addition to the services listed below, the above information also applies to AI-assisted functions of other systems we use, in particular our ticketing system (see the section „Contact and enquiry management“).

Video conferences, online meetings, webinars and screen sharing

We use platforms and applications of other providers (hereinafter referred to as „conference platforms“) for the purposes of conducting video and audio conferences, webinars and other types of video and audio meetings (hereinafter collectively referred to as „conference“). When selecting the conference platforms and their services, we observe the statutory requirements.

Data processed by conference platforms: In the course of participation in a conference, the conference platforms process the personal data of participants set out below. The scope of the processing depends, on the one hand, on which data are required in the context of a specific conference (e.g. provision of access data or real names) and which optional information is provided by the participants. In addition to processing for the purpose of conducting the conference, participants‘ data may also be processed by the conference platforms for security purposes or service optimisation. The data processed include personal details (first name, surname), contact information (email address, telephone number), access data (access codes or passwords), profile pictures, information on professional position/function, the IP address of the internet connection, information on the participants‘ devices, their operating system, the browser and its technical and language settings, information on the content of the communication processes, i.e. entries in chats as well as audio and video data, and the use of other available functions (e.g. surveys). The content of communications is encrypted to the extent technically provided by the conference providers. Where participants are registered as users with the conference platforms, further data may be processed in accordance with the agreement with the respective conference provider.

Logging and recordings: If text entries, participation results (e.g. from surveys) as well as video or audio recordings are logged, this will be communicated transparently to the participants in advance and, where necessary, their consent will be requested.

Data protection measures for participants: Please refer to the privacy notices of the conference platforms for details of the processing of your data by them, and select the security and data protection settings that are optimal for you within the settings of the conference platforms. Please also ensure data protection and the protection of personal privacy in the background of your recording for the duration of a video conference (e.g. by informing housemates, locking doors and, where technically possible, using the function for blurring the background). Links to the conference rooms as well as access data may not be passed on to unauthorised third parties.

Information on legal bases: Insofar as, in addition to the conference platforms, we also process users‘ data and ask users for their consent to the use of the conference platforms or certain functions (e.g. agreement to a recording of conferences), the legal basis for the processing is this consent. Furthermore, our processing may be necessary for the fulfilment of our contractual obligations (e.g. in participant lists, in the case of the processing of meeting results, etc.). In all other respects, users‘ data are processed on the basis of our legitimate interests in efficient and secure communication with our communication partners.

  • Types of data processed: Master data (e.g. full name, residential address, contact information, customer number, etc.); Contact data (e.g. postal and email addresses or telephone numbers); Content data (e.g. textual or pictorial messages and contributions as well as the information relating to them, such as details of authorship or the time of creation); Usage data (e.g. page views and time spent, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions); Image and/or video recordings (e.g. photographs or video recordings of a person); Audio recordings. Log data (e.g. log files concerning logins or the retrieval of data or access times).
  • Data subjects: Communication partners; Users (e.g. website visitors, users of online services). Persons depicted.
  • Purposes of processing and legitimate interests: Provision of contractual services and fulfilment of contractual obligations; Communication. Office and organisational procedures.
  • Retention and deletion: Deletion in accordance with the information provided in the section „General information on data storage and deletion“.
  • Legal bases: Legitimate interests (Art. 6 (1) sentence 1 (f) GDPR).

Further information on processing operations, procedures and services:

  • Microsoft Teams: Used for conducting online events and conferences as well as for communication with internal and external participants. Voice transmission, direct messaging, group communication and collaboration functions are used; name, business contact details, work profile, participation and content (audio/video, speech, chat, files, speech transcription) are processed for the purposes of and in the interest of increasing efficiency and productivity, cost efficiency, flexibility, mobility, improved communication, IT security, use of a central platform and Microsoft’s business operations. Audio signals are generally not stored, except where recording is activated. Meeting and conference recordings are stored by default for 90 days unless a different period is specified. Chat and file content is stored in accordance with the policies determined by the administrator or the user; no automatic deletion is preset. Channels must be renewed every 180 days, otherwise the content is deleted. In addition, system-generated log, diagnostic and metadata are processed and diagnostic data are collected for product stability, security and improvement; Service provider: Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland; Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA; Legal bases: Legitimate interests (Art. 6 (1) sentence 1 (f) GDPR); Website: https://www.microsoft.com/en/microsoft-teams/; Privacy policy: https://privacy.microsoft.com/en-us/privacystatement, security information: https://www.microsoft.com/en-us/trustcenter. Basis for third-country transfers: Data Privacy Framework (DPF), Standard Contractual Clauses (https://www.microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA).

Cloud services

We use software services accessible via the internet and executed on the servers of their providers (so-called „cloud services“, also referred to as „software as a service“) for the storage and management of content (e.g. document storage and management, exchange of documents, content and information with specific recipients, or publication of content and information).

In this context, personal data may be processed and stored on the providers‘ servers, insofar as these data form part of communication processes with us or are otherwise processed by us as set out in this privacy policy. These data may include, in particular, master data and contact data of users, data on cases, contracts, other processes and their content. The providers of the cloud services also process usage data and metadata, which they use for security purposes and for service optimisation.

Insofar as we use cloud services to provide forms or other documents and content for other users or publicly accessible websites, the providers may store cookies on users‘ devices for the purposes of web analysis or in order to remember users‘ settings (e.g. in the case of media control).

  • Types of data processed: Master data (e.g. full name, residential address, contact information, customer number, etc.); Contact data (e.g. postal and email addresses or telephone numbers); Content data (e.g. textual or pictorial messages and contributions as well as the information relating to them, such as details of authorship or the time of creation). Usage data (e.g. page views and time spent, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions).
  • Data subjects: Prospective customers; Communication partners. Business and contractual partners.
  • Purposes of processing and legitimate interests: Office and organisational procedures. Information technology infrastructure (operation and provision of information systems and technical devices (computers, servers, etc.)).
  • Retention and deletion: Deletion in accordance with the information provided in the section „General information on data storage and deletion“.
  • Legal bases: Legitimate interests (Art. 6 (1) sentence 1 (f) GDPR).

Further information on processing operations, procedures and services:

  • Microsoft 365 and Microsoft cloud services: Provision of applications, protection of data and IT systems, and use of system-generated log, diagnostic and metadata for the performance of the contract by Microsoft. Contact data (name, email address), content data (files, comments, profiles), software setup and inventory data, device connectivity and configuration data, work interactions (badge swipe) as well as log data and metadata are processed. The processing takes place for the purposes of increasing efficiency and productivity, cost efficiency, flexibility, mobility, improved communication, integration of Microsoft services, IT security and Microsoft’s business operations. The retention of data is governed by the respective documents and company policies; for Defender (protection of data and IT systems) up to 12 months, for print management 10 days. In addition, diagnostic data are collected for product stability and improvement. The functions used also include AI-assisted assistance functions (Microsoft Copilot); in this respect we refer to the section „Use of AI systems for processing enquiries“. Service provider: Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland; Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA; Legal bases: Legitimate interests (Art. 6 (1) sentence 1 (f) GDPR); Website: https://microsoft.com; Privacy policy: https://privacy.microsoft.com/en-us/privacystatement, security information: https://www.microsoft.com/en-us/trustcenter; Data processing agreement: https://www.microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA. Basis for third-country transfers: Data Privacy Framework (DPF), Standard Contractual Clauses (https://www.microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA).
  • STARFACE Cloud (telephone system): Provision of a cloud-based telephone system for handling incoming and outgoing calls as well as for internal and external corporate communication. In particular, communication and connection data (telephone numbers of callers and called parties, date and time of calls, call duration), voicemail data where applicable, device and configuration data, user account data (name, business contact details) as well as system-generated log data and metadata are processed. The processing takes place for the purposes of ensuring efficient and reliable business communication, IT security, error analysis, system stability, as well as for the organisation and documentation of communication processes. The retention of connection and log data is governed by the respective system settings and internal company policies. Service provider: STARFACE GmbH, Stephanienstraße 102, 76133 Karlsruhe, Germany; Website: https://www.starface.com; Privacy policy: https://www.starface.com/de/datenschutz/. Legal bases: Legitimate interests (Art. 6 (1) sentence 1 (f) GDPR) in efficient and secure corporate communication as well as – where applicable – performance of a contract and pre-contractual measures (Art. 6 (1) sentence 1 (b) GDPR); Data processing agreement: Provided by the service provider. Basis for third-country transfers: The processing takes place within the European Union.

Newsletter and electronic notifications

We send newsletters, emails and other electronic notifications (hereinafter „newsletter“) exclusively with the consent of the recipients (double opt-in) or on the basis of a statutory provision. In addition, we process email addresses for product information sent to existing customers on the basis of Section 7 (3) of the German Act Against Unfair Competition (UWG) (see below).

Insofar as the content of a newsletter is described in the course of registration, this content is decisive for the consent of the users. As a rule, providing your email address is sufficient to register for our newsletter. However, in order to be able to offer you a personalised service, we may ask you to provide your name for a personal form of address in the newsletter, or further information if this is necessary for the purpose of the newsletter.

Deletion and restriction of processing: We may store the email addresses that have been unsubscribed for up to three years on the basis of our legitimate interests before deleting them, in order to be able to provide evidence of consent previously given. The processing of these data is restricted to the purpose of a potential defence against claims. An individual request for deletion is possible at any time, provided that the former existence of consent is confirmed at the same time. In the case of obligations to permanently observe objections, we reserve the right to store the email address solely for this purpose in a blocking list (a so-called „blocklist“).

The registration procedure is logged on the basis of our legitimate interests for the purpose of providing evidence that it was carried out properly. Insofar as we commission a service provider with the dispatch of emails, this takes place on the basis of our legitimate interests in an efficient and secure dispatch system.

Content:

Information about us, our services, campaigns and offers.

  • Types of data processed: Master data (e.g. full name, residential address, contact information, customer number, etc.); Contact data (e.g. postal and email addresses or telephone numbers); Meta, communication and process data (e.g. IP addresses, timestamps, identification numbers, persons involved). Usage data (e.g. page views and time spent, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions).
  • Data subjects: Communication partners.
  • Purposes of processing and legitimate interests: Direct marketing (e.g. by email or post). Reach measurement (e.g. access statistics, recognition of returning visitors).
  • Legal bases: Consent (Art. 6 (1) sentence 1 (a) GDPR). Legitimate interests (Art. 6 (1) sentence 1 (f) GDPR).
  • Right to object (opt-out): You may cancel receipt of our newsletter at any time, i.e. withdraw your consent or object to further receipt. You will find a link to cancel the newsletter either at the end of each newsletter, or you may otherwise use one of the contact options stated above, preferably email, for this purpose.

Further information on processing operations, procedures and services:

  • Measurement of open and click rates: The newsletters contain a so-called „web beacon“, i.e. a pixel-sized file which is retrieved from our server, or from that of the dispatch service provider if we use one, when the newsletter is opened. In the course of this retrieval, technical information such as details of the browser and your system, as well as your IP address and the time of retrieval, is initially collected. This information is used for the technical improvement of our newsletter on the basis of the technical data or the target groups and their reading behaviour, based on their places of retrieval (which can be determined with the aid of the IP address) or the access times. This analysis also includes determining whether and when the newsletters are opened and which links are clicked. The information collected is attributed to the individual newsletter recipients and stored in their profiles until deletion. On this basis, user profiles are created in which usage behaviour and user characteristics are stored. The measurement of open and click rates, the storage of the measurement results in users‘ profiles and their further processing take place on the basis of users‘ consent. Unfortunately, a separate withdrawal of the performance measurement is not possible; in this case the entire newsletter subscription must be cancelled or objected to. In this case, the stored profile information is deleted; Legal bases: Consent (Art. 6 (1) sentence 1 (a) GDPR).
  • Reminder emails relating to the ordering process: If users do not complete an ordering process, we may remind users of the ordering process by email and send them a link to continue it. This function may be useful, for example, where the purchase process could not be continued due to a browser crash, oversight or forgetfulness. Dispatch takes place on the basis of consent which users may withdraw at any time; Legal bases: Consent (Art. 6 (1) sentence 1 (a) GDPR).
  • Product information following an enquiry or to existing customers (without separate consent): If you have purchased a product or service from us or have provided us with your email address in connection with such a service (e.g. when downloading our software), we use your email address in order to send you information about our own similar products and services. The legal basis is our legitimate interest in direct marketing pursuant to Art. 6 (1) sentence 1 (f) GDPR in conjunction with Section 7 (3) UWG. You may object to this use at any time, for example via the unsubscribe link in each email; we will then add your address to a blocking list. No costs will be incurred by you for this other than the transmission costs according to the basic rates. The processing concerns master data and contact data.
  • Brevo: Email dispatch and automation services; Service provider: Sendinblue GmbH, Köpenicker Str. 126, 10179 Berlin, Germany; Legal bases: Legitimate interests (Art. 6 (1) sentence 1 (f) GDPR); Website: https://www.brevo.com/; Privacy policy: https://www.brevo.com/legal/privacypolicy/. Data processing agreement: Provided by the service provider.

Web analytics, monitoring and optimisation

Web analytics (also referred to as „reach measurement“) serves the evaluation of the visitor flows of our online offer and may comprise behaviour, interests or demographic information about visitors, such as age or gender, in the form of pseudonymous values. With the aid of reach analysis we can, for example, identify at what time our online offer or its functions or content are used most frequently, or invite reuse. Likewise, it enables us to understand which areas require optimisation.

In addition to web analytics, we may also use testing procedures, for example in order to test and optimise different versions of our online offer or its components.

Unless stated otherwise below, profiles, i.e. data aggregated for a usage process, may be created for these purposes, and information may be stored in a browser or on a device and subsequently read. The information collected includes, in particular, websites visited and the elements used there, as well as technical information such as the browser used, the computer system used and information on times of use. Insofar as users have consented to the collection of their location data by us or by the providers of the services we use, the processing of location data is also possible.

In addition, users‘ IP addresses are stored. However, we use an IP masking procedure (i.e. pseudonymisation by truncating the IP address) to protect users. In general, no plain data of users (such as email addresses or names) are stored in the context of web analytics, A/B testing and optimisation, but rather pseudonyms. This means that neither we nor the providers of the software used know the actual identity of the users, but only the information stored in their profiles for the purpose of the respective procedures.

Information on legal bases: Insofar as we ask users for their consent to the use of third-party providers, the legal basis for the data processing is that consent. Otherwise, users‘ data are processed on the basis of our legitimate interests (i.e. an interest in efficient, economical and recipient-friendly services). In this context, we would also like to draw your attention to the information on the use of cookies in this privacy policy.

  • Types of data processed: Usage data (e.g. page views and time spent, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions). Meta, communication and process data (e.g. IP addresses, timestamps, identification numbers, persons involved).
  • Data subjects: Users (e.g. website visitors, users of online services).
  • Purposes of processing and legitimate interests: Reach measurement (e.g. access statistics, recognition of returning visitors); Profiles with user-related information (creation of user profiles); Provision of our online offer and user-friendliness. Tracking (e.g. interest- or behaviour-based profiling, use of cookies).
  • Retention and deletion: Deletion in accordance with the information provided in the section „General information on data storage and deletion“. Storage of cookies for up to 2 years (unless stated otherwise, cookies and similar storage methods may be stored on users‘ devices for a period of two years).
  • Security measures: IP masking (pseudonymisation of the IP address).
  • Legal bases: Consent (Art. 6 (1) sentence 1 (a) GDPR). Legitimate interests (Art. 6 (1) sentence 1 (f) GDPR).

Further information on processing operations, procedures and services:

  • Google Analytics: We use Google Analytics to measure and analyse the use of our online offer on the basis of a pseudonymous user identification number. This identification number does not contain any unique data such as names or email addresses. It serves to attribute analytics information to a device in order to identify which content users have accessed within one or various usage processes, which search terms they have used, whether they have accessed it again or have interacted with our online offer. Likewise, the time of use and its duration are stored, as well as the sources of the users referring to our online offer and technical aspects of their devices and browsers.
    Pseudonymous profiles of users are created with information from the use of different devices, whereby cookies may be used. Google Analytics does not log or store individual IP addresses for EU users. However, Analytics provides coarse geographical location data by deriving the following metadata from IP addresses: city (and the derived latitude and longitude of the city), continent, country, region, subcontinent (and ID-based counterparts). For EU traffic, the IP address data are used exclusively for this derivation of geolocation data before they are immediately deleted. They are not logged, are not accessible and are not used for any further purposes. When Google Analytics collects measurement data, all IP queries are carried out on EU-based servers before the traffic is forwarded to Analytics servers for processing; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases: Consent (Art. 6 (1) sentence 1 (a) GDPR); Website: https://marketingplatform.google.com/about/analytics/; Security measures: IP masking (pseudonymisation of the IP address); Privacy policy: https://policies.google.com/privacy; Data processing agreement: https://business.safety.google/adsprocessorterms/; Basis for third-country transfers: Data Privacy Framework (DPF), Standard Contractual Clauses (https://business.safety.google/adsprocessorterms); Right to object (opt-out): Opt-out plug-in: https://tools.google.com/dlpage/gaoptout, settings for the display of advertisements: https://myadcenter.google.com/personalizationoff. Further information: https://business.safety.google/adsservices/ (types of processing and data processed).
  • Google Tag Manager: We use Google Tag Manager, a software from Google which enables us to manage so-called website tags centrally via a user interface. Tags are small code elements on our website which serve to record and analyse visitor activities. This technology supports us in improving our website and the content offered on it. Google Tag Manager itself does not create user profiles, does not store cookies with user profiles and does not carry out any independent analyses. Its function is limited to simplifying and making more efficient the integration and management of tools and services which we use on our website. Nevertheless, when Google Tag Manager is used, the IP address of users is transmitted to Google, which is necessary for technical reasons in order to implement the services we use. Cookies may also be set in this process. However, this data processing only takes place where services are integrated via the Tag Manager. For more detailed information on these services and their data processing, we refer to the further sections of this privacy policy; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases: Consent (Art. 6 (1) sentence 1 (a) GDPR); Website: https://marketingplatform.google.com; Privacy policy: https://policies.google.com/privacy; Data processing agreement:
    https://business.safety.google/adsprocessorterms. Basis for third-country transfers: Data Privacy Framework (DPF), Standard Contractual Clauses (https://business.safety.google/adsprocessorterms).
  • Microsoft Clarity: Web analytics, reach measurement and analysis of user behaviour in relation to the use of and interest in functions and content, as well as their duration of use, on the basis of a pseudonymous user identification number and profiling; Service provider: Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland; Legal bases: Consent (Art. 6 (1) sentence 1 (a) GDPR); Website: https://clarity.microsoft.com; Privacy policy: https://privacy.microsoft.com/en-us/privacystatement; Data processing agreement: https://www.microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA. Basis for third-country transfers: Data Privacy Framework (DPF), Standard Contractual Clauses (https://www.microsoft.com/en-us/privacy/privacystatement).

Customer reviews and rating procedures

We participate in review and rating procedures in order to evaluate, optimise and promote our services. Where users rate us via the participating rating platforms or procedures, or otherwise provide feedback, the general terms and conditions or terms of use and the privacy notices of the providers apply in addition. As a rule, rating also requires registration with the respective providers.

In order to ensure that the persons providing a rating have actually used our services, we transmit the data required for this purpose relating to the customer and the service used to the respective rating platform with the customer’s consent (including name, email address and order number or item number). These data are used solely to verify the authenticity of the user.

  • Types of data processed: Contract data (e.g. subject matter of the contract, term, customer category); Usage data (e.g. page views and time spent, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions). Meta, communication and process data (e.g. IP addresses, timestamps, identification numbers, persons involved).
  • Data subjects: Service recipients and clients. Users (e.g. website visitors, users of online services).
  • Purposes of processing and legitimate interests: Feedback (e.g. collecting feedback via an online form). Marketing.
  • Legal bases: Legitimate interests (Art. 6 (1) sentence 1 (f) GDPR).

Further information on processing operations, procedures and services:

  • Google Customer Reviews: Service for obtaining and/or displaying customer satisfaction and customer opinions; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases: Legitimate interests (Art. 6 (1) sentence 1 (f) GDPR); Website: https://www.google.com/; Privacy policy: https://policies.google.com/privacy; Basis for third-country transfers: Data Privacy Framework (DPF); Further information: In the course of obtaining customer reviews, an identification number and the time of the business transaction to be rated are processed, and in the case of review requests sent directly to customers, the customer’s email address and their information on the country of residence as well as the review details themselves. Further information on the types of processing and the data processed: https://business.safety.google/adsservices/. Data processing terms for Google advertising products: information on the services, data processing terms between controllers and Standard Contractual Clauses for third-country transfers of data: https://business.safety.google/adscontrollerterms.

Presence on social networks (social media)

We maintain online presences within social networks and, in this context, process user data in order to communicate with users active there or to offer information about us.

We point out that user data may be processed outside the territory of the European Union in this context. This may give rise to risks for users, because, for example, the enforcement of users‘ rights could be made more difficult.

Furthermore, users‘ data within social networks are generally processed for market research and advertising purposes. For example, usage profiles may be created on the basis of usage behaviour and the resulting interests of users. The latter may in turn be used, for example, to place advertisements within and outside the networks which are presumed to correspond to the interests of users. For this reason, cookies are generally stored on users‘ computers in which usage behaviour and users‘ interests are stored. In addition, data may also be stored in the usage profiles independently of the devices used by the users (in particular where they are members of the respective platforms and are logged in there).

For a detailed presentation of the respective forms of processing and the options for objection (opt-out), we refer to the privacy policies and information of the operators of the respective networks.

In the case of requests for access and the assertion of data subject rights, we also point out that these can be asserted most effectively with the providers. Only the latter have access to the user data in each case and can directly take appropriate measures and provide information. Should you nevertheless require assistance, you may contact us.

  • Types of data processed: Contact data (e.g. postal and email addresses or telephone numbers); Content data (e.g. textual or pictorial messages and contributions as well as the information relating to them, such as details of authorship or the time of creation). Usage data (e.g. page views and time spent, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions).
  • Data subjects: Users (e.g. website visitors, users of online services).
  • Purposes of processing and legitimate interests: Communication; Feedback (e.g. collecting feedback via an online form). Public relations.
  • Retention and deletion: Deletion in accordance with the information provided in the section „General information on data storage and deletion“.
  • Legal bases: Legitimate interests (Art. 6 (1) sentence 1 (f) GDPR).

Further information on processing operations, procedures and services:

  • Instagram: Social network, enables the sharing of photos and videos, commenting on and favouriting posts, sending messages, subscribing to profiles and pages; Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Legal bases: Legitimate interests (Art. 6 (1) sentence 1 (f) GDPR); Website: https://www.instagram.com; Privacy policy: https://privacycenter.instagram.com/policy/. Basis for third-country transfers: Data Privacy Framework (DPF).
  • Facebook pages: Profiles within the social network Facebook – The controller is jointly responsible with Meta Platforms Ireland Limited for the collection and transmission of data of visitors to our Facebook page („fan page“). This includes in particular information about user behaviour (e.g. content viewed or interacted with, actions carried out) as well as device information (e.g. IP address, operating system, browser type, language settings, cookie data). Further details can be found in the Facebook data policy: https://www.facebook.com/privacy/policy/. Facebook also uses these data in order to provide us, via the „Page Insights“ service, with statistical evaluations which give an indication of how people interact with our page and its content. The basis for this is an agreement with Facebook („Information about Page Insights“: https://www.facebook.com/legal/terms/page_controller_addendum), which governs, among other things, security measures and the exercise of data subject rights. Further information can be found here: https://www.facebook.com/legal/terms/information_about_page_insights_data. Users may therefore address requests for access or deletion directly to Facebook. Users‘ rights (in particular access, deletion, objection, complaint to a supervisory authority) remain unaffected by this. The joint responsibility is limited exclusively to the collection of the data by Meta Platforms Ireland Limited (EU). Meta Platforms Ireland Limited alone is responsible for the further processing, including any transmission to Meta Platforms Inc. in the USA; Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Legal bases: Legitimate interests (Art. 6 (1) sentence 1 (f) GDPR); Website: https://www.facebook.com; Privacy policy: https://www.facebook.com/privacy/policy/. Basis for third-country transfers: Data Privacy Framework (DPF), Standard Contractual Clauses (https://www.facebook.com/legal/EU_data_transfer_addendum).
  • LinkedIn: Social network – We are jointly responsible with LinkedIn Ireland Unlimited Company for the collection (but not the further processing) of data of visitors which are used to create the „Page Insights“ (statistics) of our LinkedIn profiles. These data include information about the types of content that users view or interact with, as well as the actions they carry out. In addition, details about the devices used are recorded, such as IP addresses, operating system, browser type, language settings and cookie data, as well as information from the user profiles such as job function, country, industry, seniority, company size and employment status. Data protection information on the processing of user data by LinkedIn can be found in LinkedIn’s privacy notices: https://www.linkedin.com/legal/privacy-policy.
    We have concluded a special agreement with LinkedIn Ireland („Page Insights Joint Controller Addendum“, https://legal.linkedin.com/pages-joint-controller-addendum), which governs in particular which security measures LinkedIn must observe and in which LinkedIn has agreed to fulfil the rights of data subjects (i.e. users may, for example, address requests for access or deletion directly to LinkedIn). Users‘ rights (in particular the right of access, deletion, objection and complaint to the competent supervisory authority) are not restricted by the agreements with LinkedIn. The joint responsibility is limited to the collection and transmission of the data to LinkedIn Ireland Unlimited Company, a company established in the EU. The further processing of the data is the sole responsibility of LinkedIn Ireland Unlimited Company, in particular as regards the transmission of the data to the parent company LinkedIn Corporation in the USA; Service provider: LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland; Legal bases: Legitimate interests (Art. 6 (1) sentence 1 (f) GDPR); Website: https://www.linkedin.com; Privacy policy: https://www.linkedin.com/legal/privacy-policy; Basis for third-country transfers: Data Privacy Framework (DPF), Standard Contractual Clauses (https://legal.linkedin.com/dpa). Right to object (opt-out): https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.
  • YouTube: Social network and video platform; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases: Legitimate interests (Art. 6 (1) sentence 1 (f) GDPR); Privacy policy: https://policies.google.com/privacy; Basis for third-country transfers: Data Privacy Framework (DPF). Right to object (opt-out): https://myadcenter.google.com/personalizationoff.
  • Xing: Social network; Service provider: New Work SE, Am Strandkai 1, 20457 Hamburg, Germany; Legal bases: Legitimate interests (Art. 6 (1) sentence 1 (f) GDPR); Website: https://www.xing.com/. Privacy policy: https://privacy.xing.com/en/privacy-policy.

Plug-ins and embedded functions and content

We integrate functional and content elements into our online offer which are obtained from the servers of their respective providers (hereinafter referred to as „third-party providers“). These may be, for example, graphics, videos or city maps (hereinafter uniformly referred to as „content“).

Integration always requires that the third-party providers of this content process the IP address of the users, since without the IP address they would not be able to send the content to their browser. The IP address is therefore necessary for the display of this content or these functions. We endeavour to use only such content whose respective providers use the IP address solely for the delivery of the content. Third-party providers may furthermore use so-called pixel tags (invisible graphics, also referred to as „web beacons“) for statistical or marketing purposes. By means of the „pixel tags“, information such as visitor traffic on the pages of this website can be evaluated. The pseudonymous information may furthermore be stored in cookies on the user’s device and may contain, among other things, technical information on the browser and the operating system, on referring websites, on the time of the visit as well as further information on the use of our online offer, but may also be combined with such information from other sources.

Information on legal bases: Insofar as we ask users for their consent to the use of third-party providers, the legal basis for the data processing is that permission. Otherwise, users‘ data are processed on the basis of our legitimate interests (i.e. an interest in efficient, economical and recipient-friendly services). In this context, we would also like to draw your attention to the information on the use of cookies in this privacy policy.

  • Types of data processed: Usage data (e.g. page views and time spent, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions); Meta, communication and process data (e.g. IP addresses, timestamps, identification numbers, persons involved). Location data (information on the geographical position of a device or a person).
  • Data subjects: Users (e.g. website visitors, users of online services).
  • Purposes of processing and legitimate interests: Provision of our online offer and user-friendliness; Provision of contractual services and fulfilment of contractual obligations; Reach measurement (e.g. access statistics, recognition of returning visitors); Tracking (e.g. interest- or behaviour-based profiling, use of cookies); Target group formation. Marketing.
  • Retention and deletion: Deletion in accordance with the information provided in the section „General information on data storage and deletion“. Storage of cookies for up to 2 years (unless stated otherwise, cookies and similar storage methods may be stored on users‘ devices for a period of two years).
  • Legal bases: Consent (Art. 6 (1) sentence 1 (a) GDPR). Legitimate interests (Art. 6 (1) sentence 1 (f) GDPR).

Further information on processing operations, procedures and services:

  • Google Maps: We integrate the maps of the „Google Maps“ service provided by Google. The data processed may include, in particular, IP addresses and location data of users; Service provider: Google Cloud EMEA Limited, 70 Sir John Rogerson’s Quay, Dublin 2, Ireland; Legal bases: Consent (Art. 6 (1) sentence 1 (a) GDPR); Website: https://mapsplatform.google.com/; Privacy policy: https://policies.google.com/privacy. Basis for third-country transfers: Data Privacy Framework (DPF).
  • reCAPTCHA: We integrate the „reCAPTCHA“ function in order to be able to detect whether entries (e.g. in online forms) are made by humans and not by automatically operating machines (so-called „bots“). The data processed may include IP addresses, information on operating systems, devices or browsers used, language settings, location, mouse movements, keystrokes, time spent on websites, previously visited websites, interactions with reCAPTCHA on other websites, cookies in certain circumstances, as well as the results of manual recognition processes (e.g. answering questions posed or selecting objects in images). The data processing takes place on the basis of our legitimate interest in protecting our online offer against abusive automated crawling and spam; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases: Legitimate interests (Art. 6 (1) sentence 1 (f) GDPR); Website: https://www.google.com/recaptcha/; Privacy policy: https://policies.google.com/privacy; Data processing agreement: https://cloud.google.com/terms/data-processing-addendum. Basis for third-country transfers: Data Privacy Framework (DPF), Standard Contractual Clauses (https://cloud.google.com/terms/sccs/eu-c2p).
  • YouTube videos: Videos stored on YouTube are embedded within our online offer. The integration of these YouTube videos takes place via a special domain with the aid of the „youtube-nocookie“ component in what is known as „enhanced privacy mode“. In „enhanced privacy mode“, until the video is started only information including your IP address and details of the browser and your device may be stored on your device in cookies or by means of comparable procedures, which YouTube requires for the output, control and optimisation of the video display. As soon as you play the videos, additional information for the analysis of usage behaviour as well as for storage in the user profile and for the personalisation of content and advertising may be processed by YouTube. The storage period for the cookies may be up to two years; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases: Consent (Art. 6 (1) sentence 1 (a) GDPR); Website: https://www.youtube.com; Privacy policy: https://policies.google.com/privacy; Basis for third-country transfers: Data Privacy Framework (DPF). Further information: https://support.google.com/youtube/answer/171780?hl=en#zippy=%2Cturn-on-privacy-enhanced-mode.

Processing of data in connection with employment relationships

Within the framework of employment relationships, personal data are processed with the aim of effectively structuring the establishment, performance and termination of such relationships. This data processing supports various operational and administrative functions which are necessary for the management of employee relations.

The data processing covers various aspects ranging from the initiation of the contract to its termination. This includes the organisation and administration of daily working hours, the management of access rights and authorisations, as well as the handling of personnel development measures and employee appraisals. The processing also serves the settlement and administration of wage and salary payments, which constitute critical aspects of contract performance.

In addition, the data processing takes into account legitimate interests of the responsible employer, such as ensuring safety in the workplace or recording performance data for the assessment and optimisation of operational processes. Furthermore, the data processing includes the disclosure of employee data within the framework of external communication and publication processes, where this is necessary for operational or legal purposes.

The processing of these data always takes place in compliance with the applicable legal framework, whereby the objective is always the creation and maintenance of a fair and efficient working environment. This also includes consideration of the data protection of the employees concerned, the anonymisation or deletion of data after the purpose of processing has been fulfilled or in accordance with statutory retention periods.

  • Types of data processed: Employee data (information on employees and other persons in an employment relationship); Payment data (e.g. bank details, invoices, payment history); Contract data (e.g. subject matter of the contract, term, customer category); Master data (e.g. full name, residential address, contact information, customer number, etc.); Contact data (e.g. postal and email addresses or telephone numbers); Content data (e.g. textual or pictorial messages and contributions as well as the information relating to them, such as details of authorship or the time of creation); Social data (data subject to social secrecy and processed, for example, by social insurance institutions, social welfare institutions or pension authorities); Log data (e.g. log files concerning logins or the retrieval of data or access times); Performance and conduct data (e.g. performance and conduct aspects such as performance appraisals, feedback from superiors, participation in training, compliance with company policies, self-assessments and conduct assessments); Working time data (e.g. start of working time, end of working time, actual working time, target working time, break times, overtime, holiday days, special leave days, sick days, absences, home-office days, business trips); Salary data (e.g. basic salary, bonus payments, premiums, tax class information, supplements for night work/overtime, tax deductions, social security contributions, net payment amount); Image and/or video recordings (e.g. photographs or video recordings of a person); Usage data (e.g. page views and time spent, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions). Meta, communication and process data (e.g. IP addresses, timestamps, identification numbers, persons involved).
  • Special categories of personal data: Health data; Religious or philosophical beliefs. Trade union membership.
  • Data subjects: Employees (e.g. staff, applicants, temporary workers and other personnel).
  • Purposes of processing and legitimate interests: Establishment and performance of employment relationships (processing of employee data within the framework of the establishment and performance of employment relationships); Business processes and economic procedures; Provision of contractual services and fulfilment of contractual obligations; Public relations; Security measures. Office and organisational procedures.
  • Legal bases: Performance of a contract and prior requests (Art. 6 (1) sentence 1 (b) GDPR); Legal obligation (Art. 6 (1) sentence 1 (c) GDPR); Legitimate interests (Art. 6 (1) sentence 1 (f) GDPR). Processing of special categories of personal data relating to healthcare, employment and social security (Art. 9 (2) (h) GDPR).

Further information on processing operations, procedures and services:

  • Working time recording: Procedures for recording the working hours of employees comprise both manual and automated methods, such as the use of time clocks, time recording software or mobile apps. This involves activities such as the entry of arrival and departure times, break times, overtime and absences. The verification and validation of the recorded working hours includes comparison with deployment or shift schedules, the checking of absences and the approval of overtime by superiors. Reports and analyses are prepared on the basis of the recorded working hours in order to provide working time records, overtime reports and absence statistics for management and the human resources department; Legal bases: Performance of a contract and prior requests (Art. 6 (1) sentence 1 (b) GDPR), Legitimate interests (Art. 6 (1) sentence 1 (f) GDPR).
  • Authorisation management: Procedures required for the definition, administration and control of access rights and user roles within a system or an organisation (e.g. creation of authorisation profiles, role- and access-based control, review and approval of access requests, regular review of access rights, tracking and auditing of user activities, creation of security policies and procedures); Legal bases: Performance of a contract and prior requests (Art. 6 (1) sentence 1 (b) GDPR), Legal obligation (Art. 6 (1) sentence 1 (c) GDPR), Legitimate interests (Art. 6 (1) sentence 1 (f) GDPR).
  • Special categories of personal data: Special categories of personal data are processed within the framework of the employment relationship or in order to comply with legal obligations. The special categories of personal data processed comprise data concerning the health, trade union membership or religious affiliation of employees. These data may, for example, be passed on to health insurance funds or be processed in order to assess the working capacity of employees, for occupational health management or for statements to the tax office; Legal bases: Performance of a contract and prior requests (Art. 6 (1) sentence 1 (b) GDPR), Legal obligation (Art. 6 (1) sentence 1 (c) GDPR), Legitimate interests (Art. 6 (1) sentence 1 (f) GDPR).
  • Sources of the data processed: Personal data are processed which were obtained within the framework of the application and/or the employment relationship of the employees. In addition, where required by law, personal data are collected from other sources. These may be tax authorities for tax-relevant information, the respective health insurance fund for information on incapacity for work, third parties such as employment agencies, or publicly accessible sources such as professional social networks within the framework of application procedures; Legal bases: Legal obligation (Art. 6 (1) sentence 1 (c) GDPR), Legitimate interests (Art. 6 (1) sentence 1 (f) GDPR).
  • Purposes of the data processing: The personal data of employees are processed primarily for the establishment, performance and termination of the employment relationship. Beyond this, the processing of these data is necessary in order to comply with legal obligations in the field of tax and social security law. In addition to these primary purposes, employee data are also used to fulfil regulatory and supervisory requirements, to optimise electronic data processing procedures and to compile internal or cross-company data, possibly including statistical data. Furthermore, employee data may be processed for the assertion of legal claims and for defence in legal disputes; Legal bases: Performance of a contract and prior requests (Art. 6 (1) sentence 1 (b) GDPR), Legal obligation (Art. 6 (1) sentence 1 (c) GDPR), Legitimate interests (Art. 6 (1) sentence 1 (f) GDPR).
  • Transmission of employee data: Employee data are processed internally only by those units which require them in order to fulfil operational, contractual and legal obligations.
    Data are passed on to external recipients only where this is required by law or where the employees concerned have given their consent. Possible scenarios for this may be requests for information from public authorities or the existence of capital-formation benefits. Furthermore, the controller may forward personal data to further recipients insofar as this is necessary in order to fulfil its contractual and legal obligations as an employer. These recipients may include: a) banks b) health insurance funds, pension insurance institutions, occupational pension providers and other social insurance institutions c) public authorities, courts (e.g. tax authorities, labour courts, further supervisory authorities within the framework of the fulfilment of reporting and disclosure obligations) d) tax and legal advisers e) garnishees in the case of wage and salary attachments f) further bodies to which legally mandatory declarations must be made.
    In addition, data may be passed on to third parties if this is necessary for communication with business partners, suppliers or other service providers. Examples of this are details in the sender area of emails or letterheads, as well as the creation of profiles on external platforms; Legal bases: Performance of a contract and prior requests (Art. 6 (1) sentence 1 (b) GDPR), Legitimate interests (Art. 6 (1) sentence 1 (f) GDPR).
  • Transmission of employee data to third countries: The transmission of employee data to third countries, i.e. countries outside the European Union (EU) and the European Economic Area (EEA), only takes place where this is necessary for the performance of the employment relationship, is required by law or where employees have given their consent to this. Employees will be informed separately of the details where this is required by law; Legal bases: Legitimate interests (Art. 6 (1) sentence 1 (f) GDPR).
  • Business trips and travel expense accounting: Procedures required for the planning, execution and settlement of business trips (e.g. booking of travel, organisation of accommodation and means of transport, administration of travel expense advances, submission and review of travel expense reports, control and posting of the costs incurred, compliance with travel policies, handling of travel expense management); Legal bases: Performance of a contract and prior requests (Art. 6 (1) sentence 1 (b) GDPR), Legal obligation (Art. 6 (1) sentence 1 (c) GDPR), Legitimate interests (Art. 6 (1) sentence 1 (f) GDPR).
  • Payroll accounting and wage bookkeeping: Procedures required for the calculation, payment and documentation of wages, salaries and other remuneration of employees (e.g. recording of working hours, calculation of deductions and supplements, payment of taxes and social security contributions, preparation of wage and salary statements, maintenance of wage accounts, reporting to the tax office and social insurance institutions); Legal bases: Performance of a contract and prior requests (Art. 6 (1) sentence 1 (b) GDPR), Legal obligation (Art. 6 (1) sentence 1 (c) GDPR).
  • Deletion of employee data: Employee data are deleted under German law where they are not required for the purpose for which they were collected, unless they must remain stored or archived on account of statutory obligations or on account of the interests of the employer. The following retention and archiving obligations are observed in this respect:
    • General personnel documents – General personnel documents (such as employment contract, reference, supplementary agreements) are retained for up to three years after the end of the employment relationship (Section 195 BGB).
      Tax-relevant documents – Tax-relevant documents in the personnel file are retained for six years (Section 147 AO, Section 257 HGB).
      Information on remuneration and working hours – Information on remuneration and working hours for (accident) insured persons with proof of wages is retained for five years (Section 165 (1) sentence 1, (4) sentence 2 SGB VII).
    • Salary lists including lists for special payments – Salary lists including lists for special payments, where an accounting voucher exists, are retained for ten years (Section 147 AO, Section 257 HGB).
    • Wage lists for interim, final and special payments – Wage lists for interim, final and special payments are retained for six years (Section 147 AO, Section 257 HGB).
    • Documents relating to salaried employees‘ insurance – Documents relating to salaried employees‘ insurance, where accounting vouchers exist, are retained for ten years (Section 147 AO, Section 257 HGB).
    • Contribution statements to social insurance institutions – Contribution statements to social insurance institutions are retained for ten years (Section 165 SGB VII).
      Wage accounts – Wage accounts are retained for six years (Section 41 (1) sentence 9 EStG).
    • Applicant data – Retained for a maximum of six months from receipt of the rejection.
    • Working time records (in the case of more than 8 hours on working days) – Retained for two years (Section 16 (2) of the German Working Hours Act (ArbZG)).
    • Application documents (following an online job advertisement) – Retained for three to a maximum of six months after receipt of the rejection (Section 26
    • Federal Data Protection Act (BDSG) new version, Section 15 (4) of the German General Equal Treatment Act (AGG)).
    • Certificates of incapacity for work – Retained for up to five years (Section 6 (1) of the German Expenditure Compensation Act (AAG)).
    • Documents relating to occupational pension schemes – Retained for 30 years (Section 18a of the German Act on the Improvement of Occupational Pensions (BetrAVG)).
    • Employees‘ illness data – Retained for twelve months after the onset of the illness, where absences in one year do not exceed six weeks.
    • Documents relating to maternity protection – Retained for two years (Section 27 (5) MuSchG).

    Legal bases: Performance of a contract and prior requests (Art. 6 (1) sentence 1 (b) GDPR), Legal obligation (Art. 6 (1) sentence 1 (c) GDPR), Legitimate interests (Art. 6 (1) sentence 1 (f) GDPR), Processing of special categories of personal data relating to healthcare, employment and social security (Art. 9 (2) (h) GDPR).

  • Personnel file management: Procedures required for the organisation, updating and administration of employee data and documents (e.g. recording of personnel master data, retention of employment contracts, references and certificates, updating of data in the event of changes, compilation of documents for employee appraisals, archiving of personnel files, compliance with data protection provisions); Legal bases: Performance of a contract and prior requests (Art. 6 (1) sentence 1 (b) GDPR), Legal obligation (Art. 6 (1) sentence 1 (c) GDPR), Legitimate interests (Art. 6 (1) sentence 1 (f) GDPR), Processing of special categories of personal data relating to healthcare, employment and social security (Art. 9 (2) (h) GDPR).
  • Personnel development, performance appraisal and employee appraisals: Procedures required in the field of the promotion and further development of employees as well as in the assessment of their performance and within the framework of employee appraisals (e.g. needs analysis for further training, planning and implementation of training measures, preparation of performance appraisals, conducting target agreement and feedback discussions, career planning and talent management, succession planning); Legal bases: Performance of a contract and prior requests (Art. 6 (1) sentence 1 (b) GDPR), Legal obligation (Art. 6 (1) sentence 1 (c) GDPR), Legitimate interests (Art. 6 (1) sentence 1 (f) GDPR), Processing of special categories of personal data relating to healthcare, employment and social security (Art. 9 (2) (h) GDPR).
  • Obligation to provide data: The controller informs employees that the provision of their data is necessary. This is generally the case where the data are necessary for the establishment and performance of the employment relationship or where their collection is required by law. The provision of data may also be necessary where employees assert claims or where claims are due to the employees. The implementation of these measures or the provision of benefits depends on the provision of these data (for example the provision of data for the purpose of receiving remuneration); Legal bases: Performance of a contract and prior requests (Art. 6 (1) sentence 1 (b) GDPR), Legal obligation (Art. 6 (1) sentence 1 (c) GDPR), Legitimate interests (Art. 6 (1) sentence 1 (f) GDPR).
  • Publication and disclosure of employee data: Employee data are published or disclosed to third parties only where, firstly, this is necessary for the performance of work tasks in accordance with the employment contract. This applies, for example, where employees are named as contact persons in correspondence, on the website or in public registers by agreement or in accordance with an agreed job description, or where the field of tasks includes representative functions. This may likewise be the case where a presentation to, or communication with, the public takes place within the framework of the performance of tasks, such as photographs within the framework of public relations work. Otherwise, employee data are published only with their consent or on the basis of legitimate interests of the employer, for example in the case of stage or group photographs taken in the course of a public event; Legal bases: Performance of a contract and prior requests (Art. 6 (1) sentence 1 (b) GDPR), Legitimate interests (Art. 6 (1) sentence 1 (f) GDPR).

Application procedure

The application procedure requires applicants to provide us with the data necessary for their assessment and selection. Which information is required follows from the job description or, in the case of online forms, from the information provided there.

In principle, the required information includes personal details such as name, address, a means of contact, as well as evidence of the qualifications necessary for a position. Upon request, we will also be pleased to inform you which information is required.

Where available, applicants are welcome to submit their applications via our online form, which is encrypted according to the state of the art. Alternatively, it is also possible to send applications to us by email. However, we would like to point out that emails are generally not sent in encrypted form on the internet. Although emails are usually encrypted during transport, this does not take place on the servers from which they are sent and received. We can therefore accept no responsibility for the security of the application on its transmission path between the sender and our server.

For the purposes of applicant search, submission of applications and selection of applicants, we may make use of applicant management or recruitment software and platforms as well as services of third-party providers, in compliance with the statutory requirements.

Applicants are welcome to contact us regarding the manner of submitting the application or to send us the application by post.

Processing of special categories of data: Insofar as special categories of personal data (Art. 9 (1) GDPR, e.g. health data such as severe disability status or ethnic origin) are requested from applicants or communicated by them within the framework of the application procedure, these are processed so that the controller or the data subject may exercise rights and comply with obligations arising from employment law and social security and social protection law, in the case of the protection of the vital interests of the applicants or of other persons, or for the purposes of preventive healthcare or occupational medicine, for the assessment of the working capacity of the employee, for medical diagnosis, for the provision of care or treatment in the health or social sector, or for the management of health or social care systems and services.

Deletion of data: The data made available by applicants may be further processed by us for the purposes of the employment relationship in the event of a successful application. Otherwise, if the application for a job offer is unsuccessful, the applicants‘ data will be deleted. Applicants‘ data will likewise be deleted if an application is withdrawn, which applicants are entitled to do at any time. Subject to a justified withdrawal by the applicants, deletion takes place at the latest after a period of six months has elapsed, so that we can answer any follow-up questions relating to the application and comply with our obligations of proof under the provisions on equal treatment of applicants. Invoices for any reimbursement of travel expenses are archived in accordance with tax law requirements.

Inclusion in an applicant pool: Inclusion in an applicant pool, where offered, takes place on the basis of consent. Applicants are informed that their consent to inclusion in the talent pool is voluntary, has no influence on the ongoing application procedure and that they may withdraw their consent at any time with effect for the future.

  • Types of data processed: Master data (e.g. full name, residential address, contact information, customer number, etc.); Contact data (e.g. postal and email addresses or telephone numbers); Content data (e.g. textual or pictorial messages and contributions as well as the information relating to them, such as details of authorship or the time of creation). Applicant data (e.g. personal details, postal and contact addresses, the documents belonging to the application and the information contained therein, such as covering letter, curriculum vitae, references, as well as further information communicated by applicants with regard to a specific position or voluntarily concerning their person or qualifications).
  • Data subjects: Applicants.
  • Purposes of processing and legitimate interests: Application procedure (establishment and any subsequent performance as well as possible subsequent termination of the employment relationship).
  • Retention and deletion: Deletion in accordance with the information provided in the section „General information on data storage and deletion“.
  • Legal bases: Application procedure as a pre-contractual or contractual relationship (Art. 6 (1) sentence 1 (b) GDPR).

Amendment and updating

We ask you to inform yourself regularly about the content of our privacy policy. We adapt the privacy policy as soon as the changes to the data processing we carry out make this necessary. We will inform you as soon as the changes require an act of cooperation on your part (e.g. consent) or other individual notification.

Insofar as we provide addresses and contact information of companies and organisations in this privacy policy, please note that the addresses may change over time and we ask you to verify the information before making contact.

Definitions of terms

This section provides you with an overview of the terms used in this privacy policy. Insofar as the terms are defined by law, their statutory definitions apply. The following explanations, by contrast, are intended primarily to aid understanding.

  • Employees: Employees are persons who are in an employment relationship, whether as staff, salaried employees or in similar positions. An employment relationship is a legal relationship between an employer and an employee which is established by an employment contract or an agreement. It includes the employer’s obligation to pay the employee remuneration while the employee performs their work. The employment relationship comprises various phases, including its establishment, in which the employment contract is concluded, its performance, in which the employee carries out their work activity, and its termination, when the employment relationship ends, whether by dismissal, termination agreement or otherwise. Employee data are all information relating to these persons and arising in the context of their employment. This includes aspects such as personal identification data, identification numbers, salary and bank details, working hours, holiday entitlements, health data and performance appraisals.
  • Master data: Master data comprise essential information which is necessary for the identification and administration of contractual partners, user accounts, profiles and similar allocations. These data may include, among other things, personal and demographic details such as names, contact information (addresses, telephone numbers, email addresses), dates of birth and specific identifiers (user IDs). Master data form the basis for any formal interaction between persons and services, institutions or systems by enabling unique allocation and communication.
  • Content data: Content data comprise information generated in the course of the creation, editing and publication of content of all kinds. This category of data may include texts, images, videos, audio files and other multimedia content published on various platforms and media. Content data are not limited to the actual content but also include metadata which provide information about the content itself, such as tags, descriptions, author information and publication dates.
  • Contact data: Contact data are essential information which enables communication with persons or organisations. They include, among other things, telephone numbers, postal addresses and email addresses, as well as means of communication such as social media handles and instant messaging identifiers.
  • Performance and conduct data: Performance and conduct data relate to information connected with how persons perform tasks or behave in a particular context, such as in an educational, work or social environment. These data may comprise indicators such as productivity, efficiency, quality of work, attendance and compliance with policies or procedures. Conduct data could comprise interactions with colleagues, communication styles, decision-making processes and reactions to various situations. These types of data are often used for performance appraisals, training and development measures as well as decision-making within organisations.
  • Meta, communication and process data: Meta, communication and process data are categories containing information about the manner in which data are processed, transmitted and managed. Metadata, also known as data about data, comprise information describing the context, origin and structure of other data. They may include details of the file size, the creation date, the author of a document and change histories. Communication data record the exchange of information between users via various channels, such as email traffic, call logs, messages on social networks and chat histories, including the persons involved, timestamps and transmission paths. Process data describe the processes and workflows within systems or organisations, including workflow documentation, logs of transactions and activities, as well as audit logs used to track and verify operations.
  • Usage data: Usage data relate to information which records how users interact with digital products, services or platforms. These data comprise a broad range of information showing how users use applications, which functions they prefer, how long they remain on particular pages and by which paths they navigate through an application. Usage data may also include the frequency of use, timestamps of activities, IP addresses, device information and location data. They are particularly valuable for analysing user behaviour, optimising user experiences, personalising content and improving products or services. In addition, usage data play a decisive role in identifying trends, preferences and possible problem areas within digital offerings.
  • Personal data: „Personal data“ means any information relating to an identified or identifiable natural person (hereinafter „data subject“); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g. cookie) or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
  • Profiles with user-related information: The processing of „profiles with user-related information“, or „profiles“ for short, comprises any form of automated processing of personal data consisting of the use of those personal data to analyse, evaluate or predict certain personal aspects relating to a natural person (depending on the type of profiling, this may include various information concerning demographics, behaviour and interests, such as interaction with websites and their content, etc.) (e.g. interests in certain content or products, click behaviour on a website or the place of residence). Cookies and web beacons are frequently used for profiling purposes.
  • Log data: Log data are information about events or activities which have been logged in a system or network. These data typically contain information such as timestamps, IP addresses, user actions, error messages and other details about the use or operation of a system. Log data are often used for the analysis of system problems, for security monitoring or for the preparation of performance reports.
  • Reach measurement: Reach measurement (also referred to as web analytics) serves the evaluation of the visitor flows of an online offer and may comprise the behaviour or interests of visitors in certain information, such as the content of web pages. With the aid of reach analysis, operators of online offerings can, for example, identify at what time users visit their web pages and which content they are interested in. This enables them, for example, to better adapt the content of the web pages to the needs of their visitors. Pseudonymous cookies and web beacons are frequently used for the purposes of reach analysis in order to recognise returning visitors and thus to obtain more precise analyses of the use of an online offer.
  • Location data: Location data arise when a mobile device (or another device with the technical prerequisites for determining location) connects to a radio cell, a WLAN or similar technical means and functions for determining location. Location data serve to indicate the geographically determinable position on Earth at which the respective device is located. Location data may be used, for example, to display map functions or other location-dependent information.
  • Tracking: „Tracking“ refers to the ability to trace the behaviour of users across several online offerings. As a rule, behavioural and interest information relating to the online offerings used is stored in cookies or on the servers of the providers of the tracking technologies (so-called profiling). This information may subsequently be used, for example, to display advertisements to users which are likely to correspond to their interests.
  • Controller: „Controller“ means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
  • Processing: „Processing“ means any operation or set of operations which is performed on personal data, whether or not by automated means. The term is broad and covers practically any handling of data, be it collection, evaluation, storage, transmission or deletion.
  • Contract data: Contract data are specific information relating to the formalisation of an agreement between two or more parties. They document the conditions under which services or products are provided, exchanged or sold. This category of data is essential for the administration and fulfilment of contractual obligations and comprises both the identification of the contracting parties and the specific terms and conditions of the agreement. Contract data may include start and end dates of the contract, the type of services or products agreed, price agreements, payment terms, termination rights, renewal options and special conditions or clauses. They serve as the legal basis for the relationship between the parties and are decisive for clarifying rights and obligations, enforcing claims and resolving disputes.
  • Payment data: Payment data comprise all information required for the settlement of payment transactions between buyers and sellers. These data are of decisive importance for e-commerce, online banking and any other form of financial transaction. They include details such as credit card numbers, bank details, payment amounts, transaction data, verification numbers and invoice information. Payment data may also contain information on the payment status, chargebacks, authorisations and fees.
  • Target group formation: Target group formation (English „custom audiences“) refers to the determination of target groups for advertising purposes, e.g. the display of advertisements. For example, on the basis of a user’s interest in certain products or topics on the internet, it may be concluded that this user is interested in advertisements for similar products or in the online shop in which they viewed the products. „Lookalike audiences“ (or similar target groups), in turn, refers to content assessed as suitable being displayed to users whose profiles or interests presumably correspond to those of the users for whom the profiles were created. Cookies and web beacons are generally used for the purposes of forming custom audiences and lookalike audiences.