Privacy Policy
Last Update: 17. Oktober 2023
Table of contents
Controller
Overview of processing operations
Relevant legal bases
Security Precautions
Transmission of Personal Data
Rights of Data Subjects
Business services
Provision of online services and web hosting
Use of Cookies
Blogs and publication media
Contact and Inquiry Management
Job Application Process
Newsletter and Electronic Communications
Commercial communication by E-Mail, Postal Mail, Fax or Telephone
Web Analysis, Monitoring and Optimization
Online Marketing
Profiles in Social Networks (Social Media)
Plugins and embedded functions and content
Controller
Wahtari nScan GmbH
Richard-Reitzner-Allee 8
85540 Haar
Germany E-mail address: info@wahtari.ai
Phone:+49 89 21 54 3000
Legal notice: https://wahtari.io/legal-notice/
Overview of processing operations
The
following table summarises the types of data processed, the purposes
for which they are processed and the concerned data subjects.
Categories of Processed Data
Inventory data.
Payment Data.
Location data.
Contact data.
Content data.
Contract data.
Usage data.
Meta, communication and process data.
Job applicant details.
Categories of Data Subjects
Prospective customers.
Communication partner.
Users.
Job applicants.
Business and contractual partners.
Purposes of Processing
Provision of contractual services and fulfillment of
contractual obligations.
Contact requests and communication.
Security measures.
Direct marketing.
Web Analytics.
Targeting.
Office and organisational procedures.
Managing and responding to inquiries.
Job Application Process.
Feedback.
Marketing.
Profiles with user-related information.
Provision of our online services and usability.
Information technology infrastructure.
Relevant legal bases
Relevant
legal bases according to the GDPR: – In the following, you will find an
overview of the legal basis of the GDPR on which we base the processing
of personal data. Please note that in addition to the provisions of the
GDPR, national data protection provisions of your or our country of
residence or domicile may apply. If, in addition, more specific legal
bases are applicable in individual cases, we will inform you of these in
the data protection declaration.
Consent
(Article 6 (1) (a) GDPR) – The data subject has given consent to the
processing of his or her personal data for one or more specific
purposes.
Performance
of a contract and prior requests (Article 6 (1) (b) GDPR) – Performance
of a contract to which the data subject is party or in order to take
steps at the request of the data subject prior to entering into a
contract.
Compliance
with a legal obligation (Article 6 (1) (c) GDPR) – Processing is
necessary for compliance with a legal obligation to which the controller
is subject.
Legitimate
Interests (Article 6 (1) (f) GDPR) – Processing is necessary for the
purposes of the legitimate interests pursued by the controller or by a
third party, except where such interests are overridden by the interests
or fundamental rights and freedoms of the data subject which require
protection of personal data.
Job
application process as a pre-contractual or contractual relationship
(Article 6 (1) (b) GDPR) – If special categories of personal data within
the meaning of Article 9 (1) GDPR (e.g. health data, such as severely
handicapped status or ethnic origin) are requested from applicants
within the framework of the application procedure, so that the
responsible person or the person concerned can carry out the obligations
and exercising specific rights of the controller or of the data subject
in the field of employment and social security and social protection
law, their processing shall be carried out in accordance with Article 9
(2)(b) GDPR , in the case of the protection of vital interests of
applicants or other persons on the basis of Article 9 (2)(c) GDPR or for
the purposes of preventive health care or occupational medicine, for
the assessment of the employee’s ability to work, for medical
diagnostics, care or treatment in the health or social sector or for the
administration of systems and services in the health or social sector
in accordance with Article 9 (2)(d) GDPR. In the case of a communication
of special categories of data based on voluntary consent, their
processing is carried out on the basis of Article 9 (2)(a) GDPR.
National
data protection regulations in Germany: In addition to the data
protection regulations of the GDPR, national regulations apply to data
protection in Germany. This includes in particular the Law on Protection
against Misuse of Personal Data in Data Processing (Federal Data
Protection Act – BDSG). In particular, the BDSG contains special
provisions on the right to access, the right to erase, the right to
object, the processing of special categories of personal data,
processing for other purposes and transmission as well as automated
individual decision-making, including profiling. Furthermore, data
protection laws of the individual federal states may apply.
Reference
to the applicability of the GDPR and the Swiss DPA: These privacy
notices serve both to provide information in accordance with the Swiss
Federal Act on Data Protection (Swiss DPA) and the General Data
Protection Regulation (GDPR).
Security Precautions
We
take appropriate technical and organisational measures in accordance
with the legal requirements, taking into account the state of the art,
the costs of implementation and the nature, scope, context and purposes
of processing as well as the risk of varying likelihood and severity for
the rights and freedoms of natural persons, in order to ensure a level
of security appropriate to the risk.
The
measures include, in particular, safeguarding the confidentiality,
integrity and availability of data by controlling physical and
electronic access to the data as well as access to, input, transmission,
securing and separation of the data. In addition, we have established
procedures to ensure that data subjects’ rights are respected, that data
is erased, and that we are prepared to respond to data threats rapidly.
Furthermore, we take the protection of personal data into account as
early as the development or selection of hardware, software and service
providers, in accordance with the principle of privacy by design and
privacy by default.
TLS/SSL
encryption (https): To protect the data of users transmitted via our
online services, we use TLS/SSL encryption. Secure Sockets Layer (SSL)
is the standard technology for securing internet connections by
encrypting the data transmitted between a website or app and a browser
(or between two servers). Transport Layer Security (TLS) is an updated
and more secure version of SSL. Hyper Text Transfer Protocol Secure
(HTTPS) is displayed in the URL when a website is secured by an SSL/TLS
certificate.
Transmission of Personal Data
In
the context of our processing of personal data, it may happen that the
data is transferred to other places, companies or persons or that it is
disclosed to them. Recipients of this data may include, for example,
service providers commissioned with IT tasks or providers of services
and content that are embedded in a website. In such cases, the legal
requirements will be respected and in particular corresponding contracts
or agreements, which serve the protection of your data, will be
concluded with the recipients of your data.
Data
Transmission within the Group of Companies: We may transfer personal
data to other companies within our group of companies or otherwise grant
them access to this data. Insofar as this disclosure is for
administrative purposes, the disclosure of the data is based on our
legitimate business and economic interests or otherwise, if it is
necessary to fulfill our contractual obligations or if the consent of
the data subjects or otherwise a legal permission is present.
Data
Transfer within the Organization: We may transfer or otherwise provide
access to personal information to other locations within our
organization. Insofar as this disclosure is for administrative purposes,
the disclosure of the data is based on our legitimate business and
economic interests or otherwise, if it is necessary to fulfill our
contractual obligations or if the consent of those concerned or
otherwise a legal permission is present.
Rights of Data Subjects
Rights
of the Data Subjects under the GDPR: As data subject, you are entitled
to various rights under the GDPR, which arise in particular from
Articles 15 to 21 of the GDPR:
Right
to Object: You have the right, on grounds arising from your particular
situation, to object at any time to the processing of your personal data
which is based on letter (e) or (f) of Article 6(1) GDPR, including
profiling based on those provisions. Where personal data are processed
for direct marketing purposes, you have the right to object at any time
to the processing of the personal data concerning you for the purpose of
such marketing, which includes profiling to the extent that it is
related to such direct marketing.
Right of withdrawal for consents: You have the right to revoke consents at any time.
Right
of access: You have the right to request confirmation as to whether the
data in question will be processed and to be informed of this data and
to receive further information and a copy of the data in accordance with
the provisions of the law.
Right
to rectification: You have the right, in accordance with the law, to
request the completion of the data concerning you or the rectification
of the incorrect data concerning you.
Right
to Erasure and Right to Restriction of Processing: In accordance with
the statutory provisions, you have the right to demand that the relevant
data be erased immediately or, alternatively, to demand that the
processing of the data be restricted in accordance with the statutory
provisions.
Right
to data portability: You have the right to receive data concerning you
which you have provided to us in a structured, common and
machine-readable format in accordance with the legal requirements, or to
request its transmission to another controller.
Complaint
to the supervisory authority: In accordance with the law and without
prejudice to any other administrative or judicial remedy, you also have
the right to lodge a complaint with a data protection supervisory
authority, in particular a supervisory authority in the Member State
where you habitually reside, the supervisory authority of your place of
work or the place of the alleged infringement, if you consider that the
processing of personal data concerning you infringes the GDPR.
Business services
We
process data of our contractual and business partners, e.g. customers
and interested parties (collectively referred to as “contractual
partners”) within the context of contractual and comparable legal
relationships as well as associated actions and communication with the
contractual partners or pre-contractually, e.g. to answer inquiries.
We
process this data in order to fulfill our contractual obligations.
These include, in particular, the obligations to provide the agreed
services, any update obligations and remedies in the event of warranty
and other service disruptions. In addition, we process the data to
protect our rights and for the purpose of administrative tasks
associated with these obligations and company organization. Furthermore,
we process the data on the basis of our legitimate interests in proper
and economical business management as well as security measures to
protect our contractual partners and our business operations from
misuse, endangerment of their data, secrets, information and rights
(e.g. for the involvement of telecommunications, transport and other
auxiliary services as well as subcontractors, banks, tax and legal
advisors, payment service providers or tax authorities). Within the
framework of applicable law, we only disclose the data of contractual
partners to third parties to the extent that this is necessary for the
aforementioned purposes or to fulfill legal obligations. Contractual
partners will be informed about further forms of processing, e.g. for
marketing purposes, within the scope of this privacy policy.
Which
data are necessary for the aforementioned purposes, we inform the
contracting partners before or in the context of the data collection,
e.g. in online forms by special marking (e.g. colors), and/or symbols
(e.g. asterisks or the like), or personally.
We
delete the data after expiry of statutory warranty and comparable
obligations, i.e. in principle after expiry of 4 years, unless the data
is stored in a customer account or must be kept for legal reasons of
archiving. The statutory retention period for documents relevant under
tax law as well as for commercial books, inventories, opening balance
sheets, annual financial statements, the instructions required to
understand these documents and other organizational documents and
accounting records is ten years and for received commercial and business
letters and reproductions of sent commercial and business letters six
years. The period begins at the end of the calendar year in which the
last entry was made in the book, the inventory, the opening balance
sheet, the annual financial statements or the management report was
prepared, the commercial or business letter was received or sent, or the
accounting document was created, furthermore the record was made or the
other documents were created.
If
we use third-party providers or platforms to provide our services, the
terms and conditions and privacy policies of the respective third-party
providers or platforms shall apply in the relationship between the users
and the providers.
Processed
data types: Inventory data (e.g. names, addresses); Payment Data (e.g.
bank details, invoices, payment history); Contact data (e.g. e-mail,
telephone numbers). Contract data (e.g. contract object, duration,
customer category).
Data subjects: Prospective customers. Business and contractual partners.
Purposes
of Processing: Provision of contractual services and fulfillment of
contractual obligations; Contact requests and communication; Office and
organisational procedures. Managing and responding to inquiries.
Legal
Basis: Performance of a contract and prior requests (Article 6 (1) (b)
GDPR); Compliance with a legal obligation (Article 6 (1) (c) GDPR).
Legitimate Interests (Article 6 (1) (f) GDPR).
Further information on processing methods, procedures and services used:
Consulting:
We process the data of our clients, clients as well as interested
parties and other clients or contractual partners (uniformly referred to
as “clients”) in order to provide them with our consulting services.
The data processed, the type, scope and purpose of the processing and
the necessity of its processing are determined by the underlying
contractual and client relationship. Insofar as it is necessary for the
fulfilment of our contract, for the protection of vital interests or by
law, or with the consent of the client, we disclose or transfer the
client’s data to third parties or agents, such as authorities, courts,
subcontractors or in the field of IT, office or comparable services,
taking into account the professional requirements;
Legal Basis: Performance of a contract and prior requests (Article 6 (1) (b) GDPR).
Project
and Development Services: We process the data of our customers and
clients (hereinafter uniformly referred to as “customers”) in order to
enable them to select, acquire or commission the selected services or
works as well as associated activities and to pay for and make available
such services or works or to perform such services or works. The
required information is indicated as such within the framework of the
conclusion of the agreement, order or equivalent contract and includes
the information required for the provision of services and invoicing as
well as contact information in order to be able to hold any
consultations. Insofar as we gain access to the information of end
customers, employees or other persons, we process it in accordance with
the legal and contractual requirements; Legal Basis: Performance of a
contract and prior requests (Article 6 (1) (b) GDPR).
Technical
and Engineering services: We process the data of our customers and
clients (hereinafter uniformly referred to as “customers”) in order to
enable them to select, acquire or commission the selected services or
works as well as associated activities and to pay for and make available
such services or works or to perform such services or works. The
required information is indicated as such within the framework of the
conclusion of the agreement, order or equivalent contract and includes
the information required for the provision of services and invoicing as
well as contact information in order to be able to hold any
consultations. Insofar as we gain access to the information of end
customers, employees or other persons, we process it in accordance with
the legal and contractual requirements; Legal Basis: Performance of a
contract and prior requests (Article 6 (1) (b) GDPR).
Provision of online services and web hosting
We
process user data in order to be able to provide them with our online
services. For this purpose, we process the IP address of the user, which
is necessary to transmit the content and functions of our online
services to the user’s browser or terminal device.
Processed
data types: Usage data (e.g. websites visited, interest in content,
access times). Meta, communication and process data (e.g. IP addresses,
time information, identification numbers, consent status).
Data subjects: Users (e.g. website visitors, users of online services).
Purposes
of Processing: Provision of our online services and usability;
Information technology infrastructure (Operation and provision of
information systems and technical devices, such as computers, servers,
etc.).). Security measures.
Legal Basis: Legitimate Interests (Article 6 (1) (f) GDPR).
Further information on processing methods, procedures and services used:
Collection
of Access Data and Log Files: The access to our online services is
logged in the form of so-called “server log files”. Server log files may
include the address and name of the web pages and files accessed, the
date and time of access, data volumes transferred, notification of
successful access, browser type and version, the user’s operating
system, referrer URL (the previously visited page) and, as a general
rule, IP addresses and the requesting provider. The server log files can
be used for security purposes, e.g. to avoid overloading the servers
(especially in the case of abusive attacks, so-called DDoS attacks) and
to ensure the stability and optimal load balancing of the servers; Legal
Basis: Legitimate Interests (Article 6 (1) (f) GDPR). Retention period:
Log file information is stored for a maximum period of 30 days and then
deleted or anonymized. Data, the further storage of which is necessary
for evidence purposes, are excluded from deletion until the respective
incident has been finally clarified.
Use of Cookies
Cookies
are small text files or other data records that store information on
end devices and read information from the end devices. For example, to
store the login status in a user account, the contents of a shopping
cart in an e-shop, the contents accessed or the functions used. Cookies
can also be used for various purposes, e.g. for purposes of
functionality, security and convenience of online offers as well as the
creation of analyses of visitor flows.
Information
on consent: We use cookies in accordance with the statutory provisions.
Therefore, we obtain prior consent from users, except when it is not
required by law. In particular, consent is not required if the storage
and reading of information, including cookies, is strictly necessary in
order to provide an information society service explicitly requested by
the subscriber or user. Essential cookies usually include cookies with
functions related to the display and operability of the onlineservice,
load balancing, security, storage of users’ preferences and choices or
similar purposes related to the provision of the main and secondary
functions of the onlineservice requested by users. The revocable consent
will be clearly communicated to the user and will contain the
information on the respective cookie use.
Information
on legal bases under data protection law: The legal basis under data
protection law on which we process users’ personal data with the use of
cookies depends on whether we ask users for consent. If users consent,
the legal basis for processing their data is their declared consent.
Otherwise, the data processed with the help of cookies is processed on
the basis of our legitimate interests (e.g. in a business operation of
our online services and improvement of its usability) or, if this is
done in the context of the fulfillment of our contractual obligations,
if the use of cookies is necessary to fulfill our contractual
obligations. For which purposes the cookies are processed by us, we do
clarify in the course of this privacy policy or in the context of our
consent and processing procedures.
Retention period: With regard to the retention period, a distinction is drawn between the following types of cookies:
Temporary
cookies (also known as “session cookies”): Temporary cookies are
deleted at the latest after a user has left an online service and closed
his or her end device (i.e. browser or mobile application).
Permanent
cookies: Permanent cookies remain stored even after the terminal device
is closed. For example, the login status can be saved, or preferred
content can be displayed directly when the user visits a website again.
Likewise, user data collected with the help of cookies can be used for
reach measurement. Unless we provide users with explicit information
about the type and storage duration of cookies (e.g., as part of
obtaining consent), users should assume that cookies are permanent and
that the storage period can be up to two years.
General
notes on revocation and objection (so-called “Opt-Out”): Users can
revoke the consents they have given at any time and object to the
processing in accordance with legal requirements. Users can restrict the
use of cookies in their browser settings, among other options (although
this may also limit the functionality of our online offering). A
objection to the use of cookies for online marketing purposes can also
be made through the websites https://optout.aboutads.info and https://www.youronlinechoices.com/.
Legal Basis: Legitimate Interests (Article 6 (1) (f) GDPR). Consent (Article 6 (1) (a) GDPR).
Further information on processing methods, procedures and services used:
Processing
Cookie Data on the Basis of Consent: We implement a consent management
solution that obtains users’ consent for the use of cookies or for the
processes and providers mentioned within the consent management
framework. This procedure is designed to solicit, log, manage, and
revoke consents, particularly regarding the use of cookies and similar
technologies employed to store, read from, and process information on
users’ devices. As part of this procedure, user consents are obtained
for the use of cookies and the associated processing of information,
including specific processing and providers named in the consent
management process. Users also have the option to manage and withdraw
their consents. Consent declarations are stored to avoid repeated
queries and to provide proof of consent according to legal requirements.
The storage is carried out server-side and/or in a cookie (so-called
opt-in cookie) or by means of comparable technologies in order to
associate the consent with a specific user or their device.If no
specific details about the providers of consent management services are
provided, the following general notes apply: The duration of consent
storage is up to two years. A pseudonymous user identifier is created,
which is stored along with the time of consent, details on the scope of
consent (e.g., relevant categories of cookies and/or service providers),
as well as information about the browser, system, and device used;
Legal Basis: Consent (Article 6 (1) (a) GDPR).
Blogs and publication media
We
use blogs or comparable means of online communication and publication
(hereinafter “publication medium”). Readers’ data will only be processed
for the purposes of the publication medium to the extent necessary for
its presentation and communication between authors and readers or for
security reasons. For the rest, we refer to the information on the
processing of visitors to our publication medium within the scope of
this privacy policy.
Processed
data types: Inventory data (e.g. names, addresses); Contact data (e.g.
e-mail, telephone numbers); Content data (e.g. text input, photographs,
videos); Usage data (e.g. websites visited, interest in content, access
times). Meta, communication and process data (e.g. IP addresses, time
information, identification numbers, consent status).
Data subjects: Users (e.g. website visitors, users of online services).
Purposes
of Processing: Provision of contractual services and fulfillment of
contractual obligations; Feedback (e.g. collecting feedback via online
form); Provision of our online services and usability; Security
measures. Managing and responding to inquiries.
Legal Basis: Legitimate Interests (Article 6 (1) (f) GDPR).
Further information on processing methods, procedures and services used:
Comment
subscriptions: When users leave comments or other contributions, their
IP addresses may be stored based on our legitimate interests. This is
done for our safety, if someone leaves illegal contents (insults,
forbidden political propaganda, etc.) in comments and contributions. In
this case, we ourselves can be prosecuted for the comment or
contribution and are therefore interested in the author’s identity.
Furthermore, we reserve the right to process user data for the purpose
of spam detection on the basis of our legitimate interests. On the same
legal basis, in the case of surveys, we reserve the right to store the
IP addresses of users for the duration of the surveys and to use cookies
in order to avoid multiple votes. The personal information provided in
the course of comments and contributions, any contact and website
information as well as the content information will be stored
permanently by us until the user objects; Legal Basis: Legitimate
Interests (Article 6 (1) (f) GDPR).
Contact and Inquiry Management
When
contacting us (e.g. via mail, contact form, e-mail, telephone or via
social media) as well as in the context of existing user and business
relationships, the information of the inquiring persons is processed to
the extent necessary to respond to the contact requests and any
requested measures.
Processed
data types: Contact data (e.g. e-mail, telephone numbers); Content data
(e.g. text input, photographs, videos); Usage data (e.g. websites
visited, interest in content, access times). Meta, communication and
process data (e.g. IP addresses, time information, identification
numbers, consent status).
Data subjects: Communication partner (Recipients of e-mails, letters, etc.).
Purposes
of Processing: Contact requests and communication; Managing and
responding to inquiries; Feedback (e.g. collecting feedback via online
form). Provision of our online services and usability.
Legal
Basis: Legitimate Interests (Article 6 (1) (f) GDPR). Performance of a
contract and prior requests (Article 6 (1) (b) GDPR).
Further information on processing methods, procedures and services used:
Contact
form: When users contact us via our contact form, e-mail or other
communication channels, we process the data provided to us in this
context to process the communicated request;
Legal
Basis: Performance of a contract and prior requests (Article 6 (1) (b)
GDPR), Legitimate Interests (Article 6 (1) (f) GDPR).
Job Application Process
The
application process requires applicants to provide us with the data
necessary for their assessment and selection. The information required
can be found in the job description or, in the case of online forms, in
the information contained therein.
In
principle, the required information includes personal information such
as name, address, a contact option and proof of the qualifications
required for a particular employment. Upon request, we will be happy to
provide you with additional information.
If
made available, applicants can submit their applications via an online
form. The data will be transmitted to us encrypted according to the
state of the art. Applicants can also send us their applications by
e-mail. Please note, however, that e-mails on the Internet are generally
not sent in encrypted form. As a rule, e-mails are encrypted during
transport, but not on the servers from which they are sent and received.
We can therefore accept no responsibility for the transmission path of
the application between the sender and the reception on our server. For
the purposes of searching for applicants, submitting applications and
selecting applicants, we may make use of the applicant management and
recruitment software, platforms and services of third-party providers in
compliance with legal requirements. Applicants are welcome to contact
us about how to submit their application or send it to us by regular
mail.
Processing of special
categories of data: To the extent that special categories of personal
data (Article 9(1) GDPR, e.g., health data, such as disability status or
ethnic origin) are requested from applicants or communicated by them
during the application process, their processing is carried out so that
the controller or the data subject can exercise rights arising from
employment law and the law of social security and social protection, in
the case of protection of vital interests of the applicants or other
persons, or for purposes of preventive or occupational medicine, for the
assessment of the employee’s work ability, for medical diagnosis, for
the provision or treatment in the health or social sector, or for the
management of systems and services in the health or social sector.
Ereasure
of data: In the event of a successful application, the data provided by
the applicants may be further processed by us for the purposes of the
employment relationship. Otherwise, if the application for a job offer
is not successful, the applicant’s data will be deleted. Applicants’
data will also be deleted if an application is withdrawn, to which
applicants are entitled at any time. Subject to a justified revocation
by the applicant, the deletion will take place at the latest after the
expiry of a period of six months, so that we can answer any follow-up
questions regarding the application and comply with our duty of proof
under the regulations on equal treatment of applicants. Invoices for any
reimbursement of travel expenses are archived in accordance with tax
regulations.
Admission to a
talent pool – Admission to a talent pool, if offered, is based on
consent. Applicants are informed that their consent to be included in
the talent pool is voluntary, has no influence on the current
application process and that they can revoke their consent at any time
for the future.
Processed
data types: Inventory data (e.g. names, addresses); Contact data (e.g.
e-mail, telephone numbers); Content data (e.g. text input, photographs,
videos). Job applicant details (e.g. Personal data, postal and contact
addresses and the documents pertaining to the application and the
information contained therein, such as cover letter, curriculum vitae,
certificates, etc., as well as other information on the person or
qualifications of applicants provided with regard to a specific job or
voluntarily by applicants).
Data subjects: Job applicants.
Purposes
of Processing: Job Application Process (Establishment and possible
later execution as well as possible later termination of the employment
relationship).
Legal Basis: Job application process as a pre-contractual or contractual relationship (Article 6 (1) (b) GDPR).
Newsletter and Electronic Communications
We
send newsletters, e-mails and other electronic communications
(hereinafter referred to as “newsletters”) only with the consent of the
recipient or a legal permission. Insofar as the contents of the
newsletter are specifically described within the framework of
registration, they are decisive for the consent of the user. Otherwise,
our newsletters contain information about our services and us.
In
order to subscribe to our newsletters, it is generally sufficient to
enter your e-mail address. We may, however, ask you to provide a name
for the purpose of contacting you personally in the newsletter or to
provide further information if this is required for the purposes of the
newsletter.
Double opt-in
procedure: The registration to our newsletter takes place in general in a
so-called Double-Opt-In procedure. This means that you will receive an
e-mail after registration asking you to confirm your registration. This
confirmation is necessary so that no one can register with external
e-mail addresses.
The
registrations for the newsletter are logged in order to be able to prove
the registration process according to the legal requirements. This
includes storing the login and confirmation times as well as the IP
address. Likewise the changes of your data stored with the dispatch
service provider are logged.
Deletion
and restriction of processing: We may store the unsubscribed email
addresses for up to three years based on our legitimate interests before
deleting them to provide evidence of prior consent. The processing of
these data is limited to the purpose of a possible defense against
claims. An individual deletion request is possible at any time, provided
that the former existence of a consent is confirmed at the same time.
In the case of an obligation to permanently observe an objection, we
reserve the right to store the e-mail address solely for this purpose in
a blocklist.
The logging of
the registration process takes place on the basis of our legitimate
interests for the purpose of proving its proper course. If we commission
a service provider to send e-mails, this is done on the basis of our
legitimate interests in an efficient and secure sending system.
Contents:
Information about us, our services, promotions and offers.
Processed
data types: Inventory data (e.g. names, addresses); Contact data (e.g.
e-mail, telephone numbers). Meta, communication and process data (e.g.
IP addresses, time information, identification numbers, consent status).
Data subjects: Communication partner (Recipients of e-mails, letters, etc.).
Purposes of Processing: Direct marketing (e.g. by e-mail or postal).
Legal Basis: Consent (Article 6 (1) (a) GDPR).
Opt-Out:
You can cancel the receipt of our newsletter at any time, i.e. revoke
your consent or object to further receipt. You will find a link to
cancel the newsletter either at the end of each newsletter or you can
otherwise use one of the contact options listed above, preferably
e-mail.
Commercial communication by E-Mail, Postal Mail, Fax or Telephone
We
process personal data for the purposes of promotional communication,
which may be carried out via various channels, such as e-mail,
telephone, post or fax, in accordance with the legal requirements.
The recipients have the right to withdraw their consent at any time or to object to the advertising communication at any time.
After
revocation or objection, we store the data required to prove the past
authorization to contact or send up to three years from the end of the
year of revocation or objection on the basis of our legitimate
interests. The processing of this data is limited to the purpose of a
possible defense against claims. Based on the legitimate interest to
permanently observe the revocation, respectively objection of the users,
we further store the data necessary to avoid a renewed contact (e.g.
depending on the communication channel, the e-mail address, telephone
number, name).
Processed data types: Inventory data (e.g. names, addresses). Contact data (e.g. e-mail, telephone numbers).
Data subjects: Communication partner (Recipients of e-mails, letters, etc.).
Purposes of Processing: Direct marketing (e.g. by e-mail or postal).
Legal Basis: Consent (Article 6 (1) (a) GDPR). Legitimate Interests (Article 6 (1) (f) GDPR).
Web Analysis, Monitoring and Optimization
Web
analysis is used to evaluate the visitor traffic on our website and may
include the behaviour, interests or demographic information of users,
such as age or gender, as pseudonymous values. With the help of web
analysis we can e.g. recognize, at which time our online services or
their functions or contents are most frequently used or requested for
repeatedly, as well as which areas require optimization.
In
addition to web analysis, we can also use test procedures, e.g. to test
and optimize different versions of our online services or their
components.
Unless otherwise
stated below, profiles, i.e. data aggregated for a usage process, can be
created for these purposes and information can be stored in a browser
or in a terminal device and read from it. The information collected
includes, in particular, websites visited and elements used there as
well as technical information such as the browser used, the computer
system used and information on usage times. If users have agreed to the
collection of their location data from us or from the providers of the
services we use, location data may also be processed.
Unless
otherwise stated below, profiles, that is data summarized for a usage
process or user, may be created for these purposes and stored in a
browser or terminal device (so-called “cookies”) or similar processes
may be used for the same purpose. The information collected includes, in
particular, websites visited and elements used there as well as
technical information such as the browser used, the computer system used
and information on usage times. If users have consented to the
collection of their location data or profiles to us or to the providers
of the services we use, these may also be processed, depending on the
provider.
The IP addresses of
the users are also stored. However, we use any existing IP masking
procedure (i.e. pseudonymisation by shortening the IP address) to
protect the user. In general, within the framework of web analysis, A/B
testing and optimisation, no user data (such as e-mail addresses or
names) is stored, but pseudonyms. This means that we, as well as the
providers of the software used, do not know the actual identity of the
users, but only the information stored in their profiles for the
purposes of the respective processes.
Processed
data types: Usage data (e.g. websites visited, interest in content,
access times). Meta, communication and process data (e.g. IP addresses,
time information, identification numbers, consent status).
Data subjects: Users (e.g. website visitors, users of online services).
Purposes
of Processing: Web Analytics (e.g. access statistics, recognition of
returning visitors). Profiles with user-related information (Creating
user profiles).
Security measures: IP Masking (Pseudonymization of the IP address).
Online Marketing
We
process personal data for the purposes of online marketing, which may
include in particular the marketing of advertising space or the display
of advertising and other content (collectively referred to as “Content”)
based on the potential interests of users and the measurement of their
effectiveness.
For these
purposes, so-called user profiles are created and stored in a file
(so-called “cookie”) or similar procedure is used by which the relevant
user information for the display of the aforementioned content is
stored. This information may include, for example, content viewed,
websites visited, online networks used, communication partners and
technical information such as the browser used, computer system used and
information on usage times and used functions. If users have consented
to the collection of their sideline data, these can also be processed.
The
IP addresses of the users are also stored. However, we use provided IP
masking procedures (i.e. pseudonymisation by shortening the IP address)
to ensure the protection of the user’s by using a pseudonym. In general,
within the framework of the online marketing process, no clear user
data (such as e-mail addresses or names) is secured, but pseudonyms.
This means that we, as well as the providers of online marketing
procedures, do not know the actual identity of the users, but only the
information stored in their profiles.
The
information in the profiles is usually stored in the cookies or similar
memorizing procedures. These cookies can later, generally also on other
websites that use the same online marketing technology, be read and
analyzed for purposes of content display, as well as supplemented with
other data and stored on the server of the online marketing technology
provider.
Exceptionally, clear
data can be assigned to the profiles. This is the case, for example, if
the users are members of a social network whose online marketing
technology we use and the network links the profiles of the users in the
aforementioned data. Please note that users may enter into additional
agreements with the social network providers or other service providers,
e.g. by consenting as part of a registration process.
As
a matter of principle, we only gain access to summarised information
about the performance of our advertisements. However, within the
framework of so-called conversion measurement, we can check which of our
online marketing processes have led to a so-called conversion, i.e. to
the conclusion of a contract with us. The conversion measurement is used
alone for the performance analysis of our marketing activities.
Unless otherwise stated, we kindly ask you to consider that cookies used will be stored for a period of two years.
Processed
data types: Usage data (e.g. websites visited, interest in content,
access times). Meta, communication and process data (e.g. IP addresses,
time information, identification numbers, consent status).
Data subjects: Users (e.g. website visitors, users of online services).
Purposes
of Processing: Web Analytics (e.g. access statistics, recognition of
returning visitors); Targeting (e.g. profiling based on interests and
behaviour, use of cookies); Marketing. Profiles with user-related
information (Creating user profiles).
Security measures: IP Masking (Pseudonymization of the IP address).
Opt-Out:
We refer to the privacy policies of the respective service providers
and the possibilities for objection (so-called “opt-out”). If no
explicit opt-out option has been specified, it is possible to deactivate
cookies in the settings of your browser. However, this may restrict the
functions of our online offer. We therefore recommend the following
additional opt-out options, which are offered collectively for each
area:
Europe: https://www.youronlinechoices.eu.
Canada: https://www.youradchoices.ca/choices.
USA: https://www.aboutads.info/choices.
Cross-regional: https://optout.aboutads.info.
Profiles in Social Networks (Social Media)
We
maintain online presences within social networks and process user data
in this context in order to communicate with the users active there or
to offer information about us.
We
would like to point out that user data may be processed outside the
European Union. This may entail risks for users, e.g. by making it more
difficult to enforce users’ rights.
In
addition, user data is usually processed within social networks for
market research and advertising purposes. For example, user profiles can
be created on the basis of user behaviour and the associated interests
of users. The user profiles can then be used, for example, to place
advertisements within and outside the networks which are presumed to
correspond to the interests of the users. For these purposes, cookies
are usually stored on the user’s computer, in which the user’s usage
behaviour and interests are stored. Furthermore, data can be stored in
the user profiles independently of the devices used by the users
(especially if the users are members of the respective networks or will
become members later on).
For a
detailed description of the respective processing operations and the
opt-out options, please refer to the respective data protection
declarations and information provided by the providers of the respective
networks.
Also in the case of
requests for information and the exercise of rights of data subjects, we
point out that these can be most effectively pursued with the
providers. Only the providers have access to the data of the users and
can directly take appropriate measures and provide information. If you
still need help, please do not hesitate to contact us.
Processed
data types: Contact data (e.g. e-mail, telephone numbers); Content data
(e.g. text input, photographs, videos); Usage data (e.g. websites
visited, interest in content, access times). Meta, communication and
process data (e.g. IP addresses, time information, identification
numbers, consent status).
Data subjects: Users (e.g. website visitors, users of online services).
Purposes of Processing: Contact requests and communication; Feedback (e.g. collecting feedback via online form). Marketing.
Legal Basis: Legitimate Interests (Article 6 (1) (f) GDPR).
Further information on processing methods, procedures and services used:
LinkedIn:
Social network; Service provider: LinkedIn Ireland Unlimited Company,
Wilton Place, Dublin 2, Ireland; Legal Basis: Legitimate Interests
(Article 6 (1) (f) GDPR); Website: https://www.linkedin.com; Privacy Policy: https://www.linkedin.com/legal/privacy-policy; Basis for third-country transfers: Data Privacy Framework (DPF); Opt-Out: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.
Further Information:
We
are jointly responsible with LinkedIn Ireland Unlimited Company for the
collection (but not the further processing) of data from visitors for
the purposes of creating „Page-Insights” (statistics) for our LinkedIn
profiles. This data includes information about the types of content that
users view or interact with, or the actions they take, as well as
information about the devices used by the users (e.g., IP addresses,
operating system, browser type, language settings, cookie data) and
details from the users’ profiles, such as job function, country,
industry, seniority, company size, and employment status. Privacy
information regarding the processing of user data by LinkedIn can be
found in LinkedIn’s privacy notices:
We have concluded a special agreement with LinkedIn Irland, the ‘Page Insights Joint Controller Addendum (the ‘Addendum’)’ (https://legal.linkedin.com/pages-joint-controller-addendum),
which specifically regulates the security measures that LinkedIn must
observe and wherein LinkedIn has agreed to fulfill the rights of the
affected parties (i.e., users can, for example, direct requests for
information or deletion directly to LinkedIn). The rights of the users
(in particular to access to information, erasure, objection, and
complaint to the competent supervisory authority) are not restricted by
the agreements with LinkedIn. The joint responsibility is limited to the
collection of data by and transmission to Ireland Unlimited Company, a
company based in the EU. The further processing of the data is the sole
responsibility of Ireland Unlimited Company, particularly regarding the
transmission of data to the parent company LinkedIn Corporation in the
USA.
X:
Social network; Service provider: Twitter International Company, One
Cumberland Place, Fenian Street, Dublin 2 D02 AX07, Ireland;
Legal
Basis:Legitimate Interests (Article 6 (1) (f) GDPR). Privacy Policy: https://twitter.com/privacy, (Settings: https://twitter.com/personalization).
YouTube:
Social network and video platform; Service provider: Google Ireland
Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal Basis:
Legitimate Interests (Article 6 (1) (f) GDPR); Privacy Policy: https://policies.google.com/privacy; Basis for third-country transfers: Data Privacy Framework (DPF). Opt-Out:https://myadcenter.google.com/personalizationoff.
Plugins and embedded functions and content
Within
our online services, we integrate functional and content elements that
are obtained from the servers of their respective providers (hereinafter
referred to as “third-party providers”). These may, for example, be
graphics, videos or city maps (hereinafter uniformly referred to as
“Content”).
The integration
always presupposes that the third-party providers of this content
process the IP address of the user, since they could not send the
content to their browser without the IP address. The IP address is
therefore required for the presentation of these contents or functions.
We strive to use only those contents, whose respective offerers use the
IP address only for the distribution of the contents. Third parties may
also use so-called pixel tags (invisible graphics, also known as “web
beacons”) for statistical or marketing purposes. The “pixel tags” can be
used to evaluate information such as visitor traffic on the pages of
this website. The pseudonymous information may also be stored in cookies
on the user’s device and may include technical information about the
browser and operating system, referring websites, visit times and other
information about the use of our website, as well as may be linked to
such information from other sources.
Processed
data types: Usage data (e.g. websites visited, interest in content,
access times); Meta, communication and process data (e.g. IP addresses,
time information, identification numbers, consent status); Inventory
data (e.g. names, addresses); Contact data (e.g. e-mail, telephone
numbers); Content data (e.g. text input, photographs, videos). Location
data (Information on the geographical position of a device or person).
Data subjects: Users (e.g. website visitors, users of online services).
Purposes
of Processing: Provision of our online services and usability;
Provision of contractual services and fulfillment of contractual
obligations; Marketing. Profiles with user-related information (Creating
user profiles).
Legal Basis: Consent (Article 6 (1) (a) GDPR). Legitimate Interests (Article 6 (1) (f) GDPR).
Further information on processing methods, procedures and services used:
Integration of third-party software, scripts or frameworks:
We
incorporate into our online services software which we retrieve from
servers of other providers (e.g. function libraries which we use for the
purpose of displaying or user-friendliness of our online services). The
respective providers collect the user’s IP address and can process it
for the purposes of transferring the software to the user’s browser as
well as for security purposes and for the evaluation and optimisation of
their services;
Legal Basis: Legitimate Interests (Article 6 (1) (f) GDPR).
Google Fonts (from Google Server):
Obtaining
fonts (and symbols) for the purpose of a technically secure,
maintenance-free and efficient use of fonts and symbols with regard to
timeliness and loading times, their uniform presentation and
consideration of possible restrictions under licensing law. The provider
of the fonts is informed of the user’s IP address so that the fonts can
be made available in the user’s browser. In addition, technical data
(language settings, screen resolution, operating system, hardware used)
are transmitted which are necessary for the provision of the fonts
depending on the devices used and the technical environment. This data
may be processed on a server of the provider of the fonts in the USA –
When visiting our online services, users’ browsers send their browser
HTTP requests to the Google Fonts Web API. The Google Fonts Web API
provides users with Google Fonts’ cascading style sheets (CSS) and then
with the fonts specified in the CCS. These HTTP requests include (1) the
IP address used by each user to access the Internet, (2) the requested
URL on the Google server, and (3) the HTTP headers, including the user
agent describing the browser and operating system versions of the
website visitors, as well as the referral URL (i.e., the web page where
the Google font is to be displayed). IP addresses are not logged or
stored on Google servers and they are not analyzed. The Google Fonts Web
API logs details of HTTP requests (requested URL, user agent, and
referring URL). Access to this data is restricted and strictly
controlled. The requested URL identifies the font families for which the
user wants to load fonts. This data is logged so that Google can
determine how often a particular font family is requested. With the
Google Fonts Web API, the user agent must match the font that is
generated for the particular browser type. The user agent is logged
primarily for debugging purposes and is used to generate aggregate usage
statistics that measure the popularity of font families. These
aggregate usage statistics are published on Google Fonts’ Analytics
page. Finally, the referral URL is logged so that the data can be used
for production maintenance and to generate an aggregate report on top
integrations based on the number of font requests. Google says it does
not use any of the information collected by Google Fonts to profile end
users or serve targeted ads; Service provider: Google Ireland Limited,
Gordon House, Barrow Street, Dublin 4, Ireland; Legal Basis: Legitimate
Interests (Article 6 (1) (f) GDPR); Website: https://fonts.google.com/; Privacy Policy: https://policies.google.com/privacy; Basis for third-country transfers: Data Privacy Framework (DPF). Further Information: https://developers.google.com/fonts/faq/privacy?hl=en.
Google
Maps: We integrate the maps of the service “Google Maps” from the
provider Google. The data processed may include, in particular, IP
addresses and location data of users; Service provider: Google Cloud
EMEA Limited, 70 Sir John Rogerson’s Quay, Dublin 2, Ireland; Legal
Basis: Consent (Article 6 (1) (a) GDPR); Website: https://mapsplatform.google.com/; Privacy Policy: https://policies.google.com/privacy. Basis for third-country transfers: Data Privacy Framework (DPF).
LinkedIn
plugins and contents: LinkedIn plugins and contents – This can include
content such as images, videos or text and buttons with which users can
share content from this online service within LinkedIn; Service
provider: LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2,
Ireland; Legal Basis: Legitimate Interests (Article 6 (1) (f) GDPR);
Website: https://www.linkedin.com; Privacy Policy: https://www.linkedin.com/legal/privacy-policy; Data Processing Agreement: https://legal.linkedin.com/dpa; Basis for third-country transfers: Data Privacy Framework (DPF). Opt-Out:https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.
OpenStreetMap:
We integrate the maps from the “OpenStreetMap” service, which are
provided based on the Open Data Commons Open Database License (ODbL) by
the OpenStreetMap Foundation (OSMF). OpenStreetMap uses user data
exclusively for the purpose of displaying map functions and caching the
selected settings. This data may particularly include the IP addresses
and location data of the users, which, however, are not collected
without their consent (typically within the settings of their devices or
browsers); Service provider: OpenStreetMap Foundation (OSMF); Legal
Basis: Legitimate Interests (Article 6 (1) (f) GDPR); Website: https://www.openstreetmap.de; Terms & Conditions: https://osmfoundation.org/wiki/Privacy_Policy. Privacy Policy: https://wiki.osmfoundation.org/wiki/Privacy_Policy.
reCAPTCHA:
We integrate the “reCAPTCHA” function to be able to recognise whether
entries (e.g. in online forms) are made by humans and not by
automatically operating machines (so-called “bots”). The data processed
may include IP addresses, information on operating systems, devices or
browsers used, language settings, location, mouse movements, keystrokes,
time spent on websites, previously visited websites, interactions with
ReCaptcha on other websites, possibly cookies and results of manual
recognition processes (e.g. answering questions asked or selecting
objects in images). The data processing is based on our legitimate
interest to protect our online services from abusive automated crawling
and spam; Service provider: Google Ireland Limited, Gordon House, Barrow
Street, Dublin 4, Ireland, , parent company: Google LLC, 1600
Amphitheatre Parkway, Mountain View, CA 94043, USA; Legal Basis:
Legitimate Interests (Article 6 (1) (f) GDPR); Website: https://www.google.com/recaptcha/; Privacy Policy: https://policies.google.com/privacy; Basis for third-country transfers: Data Privacy Framework (DPF). Opt-Out: Opt-Out-Plugin: https://tools.google.com/dlpage/gaoptout?hl=en, Settings for the Display of Advertisements: https://myadcenter.google.com/personalizationoff.
YouTube
videos: Video contents; Service provider: Google Ireland Limited,
Gordon House, Barrow Street, Dublin 4, Ireland, , parent company: Google
LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; Legal
Basis: Consent (Article 6 (1) (a) GDPR); Website: https://www.youtube.com;
Privacy Policy: https://policies.google.com/privacy; Basis for third-country transfers: Data Privacy Framework (DPF). Opt-Out: Opt-Out-Plugin: https://tools.google.com/dlpage/gaoptout?hl=en, Settings for the Display of Advertisements: https://myadcenter.google.com/personalizationoff.
YouTube-Videos:
Video content; YouTube videos are integrated via a special domain
(recognizable by the component “youtube-nocookie”) in the so-called ”
enhanced data protection mode”, whereby no cookies on user activities
are collected in order to personalise the video playback. Nevertheless,
information on the user’s interaction with the video (e.g. remembering
the last playback point) may be stored; Service provider: Google Ireland
Limited, Gordon House, Barrow Street, Dublin 4, Ireland, parent
company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043,
USA; Legal Basis: Consent (Article 6 (1) (a) GDPR); Website: https://www.youtube.com; Privacy Policy: https://policies.google.com/privacy. Basis for third-country transfers: Data Privacy Framework (DPF).
Xing
plugins and buttons: Xing plugins and buttons – This can include
content such as images, videos or text and buttons with which users can
share content from this online service within Xing; Service provider:
New Work SE, Am Strandkai 1, 20457 Hamburg, Germany; Legal Basis:
Legitimate Interests (Article 6 (1) (f) GDPR); Website: https://www.xing.com.
Privacy Policy: https://privacy.xing.com/en.
Use of SalesViewer® technology:
This
website uses SalesViewer® technology from SalesViewer® GmbH on the
basis of the website operator’s legitimate interests (Section 6
paragraph 1 lit.f GDPR) in order to collect and save data on marketing,
market research and optimisation purposes. In order to do this, a
javascript based code, which serves to capture company-related data and
according website usage. The data captured using this technology are
encrypted in a non-retrievable one-way function (so-called hashing). The
data is immediately pseudonymised and is not used to identify website
visitors personally.
The data stored by SalesViewer® will be deleted
as soon as they are no longer required for their intended purpose and
there are no legal obligations to retain them. The data recording and
storage can be repealed at any time with immediate effect for the
future, by clicking on https://www.salesviewer.com/opt-out
in order to prevent SalesViewer® from recording your data. In this
case, an opt-out cookie for this website is saved on your device. If you
delete the cookies in the browser, you will need to click on this link
again.