Privacy Policy

1. Introduction

With this privacy policy, Planerio GmbH (hereinafter also referred to as “Planerio” or “we”) informs you about the nature, scope, and purpose of the processing of personal data (hereinafter also referred to as “data”) within our digital shift planning platform and the associated websites (e.g., www.planerio.de, www.planer.io) as well as associated local and mobile applications, functions, and content, and external online presences, such as our social media profiles (hereinafter collectively referred to as “online services”). With regard to the terminology used (e.g., “processing”, “controller”, etc.), we refer to the definitions in Art. 4 of the European General Data Protection Regulation (hereinafter referred to as “GDPR”).

Our online services enable digital shift and staff planning, time tracking, and payroll. As a user of our online services, you and the company for which you work (hereinafter also referred to as the “company” or “customer”) can store and manage the data required for shift planning, time tracking, and payroll. Each user has their own access with different rights and options for entering and retrieving data. The use of our online services requires the processing of personal data by Planerio.

Planerio uses personal data in accordance with the provisions of the GDPR, the Federal Data Protection Act (hereinafter referred to as “BDSG”), and the Telecommunications Digital Services Data Protection Act (hereinafter referred to as “TDDDG”). Planerio ensures compliance with the currently relevant security standards. The hosting servers used by Planerio are located in Germany, and the providers are certified according to DIN ISO/IEC 27001.

2. Controller and Data Protection Officer

Controller:

Planerio GmbH
Oberanger 32
80331 Munich
Email: [email protected]

Data Protection Officer:

Data Protection Officer of Planerio GmbH
c/o TÜV SÜD Akademie GmbH
Westendstraße 160
80339 Munich

Email: [email protected]
www.tuvsud.com

3. Principles of Data Processing

3.1. Categories of Data Subjects

Visitors and users of the online services as well as customers, interested parties, and business partners, as well as employees and applicants (hereinafter individually and collectively also referred to as “users”).

3.2. Types of Processed Data

To provide our online services, we process the following data from our users:

  • Master data (e.g., names, addresses).
  • Contact details (e.g., email, phone numbers).
  • Content data (e.g., text entries, uploaded documents).
  • Usage data (e.g., visited websites, interest in content, access times).
  • Meta/communication data (e.g., device information, IP addresses).

For the purpose of providing contractual services, customer service and support, marketing, advertising and market research, and applicant management, we additionally process from our users:

  • Contract data (e.g., subject matter of the contract, term, customer category),
  • General personal data (e.g., first and last name) and (business) contact details (e.g., address, email address, phone number) of the contact persons
  • Payment data (e.g., bank details, payment history)
  • Shift planning data (e.g., working hours, annual leave, training and other absences, qualifications, deployment preferences, and shift preferences).
  • Working time documentation and payroll data (e.g., timestamp, absences including reason, wages/salary, overtime regulations).
  • Applicant data (e.g., personal details, postal and contact addresses, documents belonging to the application and the information contained therein, such as cover letter, CV, certificates, as well as further information regarding a specific position or voluntarily provided by applicants regarding their person or qualification)
  • Location data (information on the geographical position of a device or a person).

3.3. Purpose of Processing

  • Provision of Planerio’s services to customers, including all processes required for this, including making the online services, their functions, and content available.
  • Responding to contact requests and communication with users.
  • Security measures.
  • Reach and conversion measurement/marketing.
  • Assertion, exercise, or defense of civil law claims.
  • Conducting application procedures.

3.4. Provision of Data to Affiliated Companies

To provide Planerio’s services to customers, including all processes required for this, general personal data (e.g., first and last name) and (business) contact details (e.g., address, email address, phone number) of the contact persons are provided to companies affiliated with Planerio according to §§ 15 ff. AktG (e.g., doctari GmbH, doctari city GmbH, Lichtfeld GmbH; hereinafter also referred to as “doctari group”).

The legal basis for providing the data to companies of the doctari group is Planerio’s legitimate interest (Art. 6 para. 1 sentence 1 lit. f GDPR) in providing the data in order to establish and maintain the most efficient group structure possible and to offer the services of Planerio and the doctari group group-wide; Planerio bases this legitimate interest within the framework of the completed company sale, in particular on the fact that only the ownership structure has changed and the company is being continued essentially identically. Planerio has a legitimate interest in processing the data in order to offer customers the best possible and most comprehensive service as a group-wide service and to fulfill the wishes or needs of customers – even beyond the services offered by Planerio – in the best possible way.

If the processing is based on Art. 6 para. 1 sentence 1 lit. f GDPR, the data subject has the right to object according to Art. 21 GDPR. Planerio will then no longer process the personal data unless Planerio can demonstrate compelling legitimate grounds for the processing which override the interests, rights, and freedoms of the data subject, or the processing serves the assertion, exercise, or defense of Planerio’s legal claims.

3.5. Terminology Used

“Personal data” means any information relating to an identified or identifiable natural person (hereinafter referred to as “data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g., cookie), or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.

“Processing” means any operation or set of operations which is performed on personal data, whether or not by automated means. The term is broad and covers practically any handling of data.

“Pseudonymization” means the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the personal data are not attributed to an identified or identifiable natural person.

“Profiling” means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyze or predict aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behavior, location, or movements.

“Controller” means the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.

“Processor” means a natural or legal person, public authority, agency, or other body which processes personal data on behalf of the controller.

“Location data” is generated when a mobile device (or another device with the technical requirements for location determination) connects to a radio cell, a WLAN, or similar technical intermediaries and functions for location determination. Location data serves to indicate at which geographically determinable position on earth the respective device is located. Location data can be used, for example, to display map functions or other information dependent on a location.

3.6. Relevant Legal Bases

In accordance with Art. 13 GDPR, we inform you of the legal bases for our data processing. If the legal basis is not mentioned in the privacy policy, the following applies: The legal basis for obtaining consent is Art. 6 para. 1 lit. a and Art. 7 GDPR; the legal basis for processing to fulfill our services and carry out (pre-)contractual measures as well as responding to inquiries is Art. 6 para. 1 lit. b GDPR; the legal basis for processing to fulfill our legal obligations is Art. 6 para. 1 lit. c GDPR; the legal basis for processing to safeguard our legitimate interests is Art. 6 para. 1 lit. f GDPR; the legal basis required for processing to assert, exercise, or defend civil law claims is § 24 para. 1 no. 2 BDSG; and the legal basis for processing within the framework of application procedures is § 26 BDSG or Art. 6 para. 1 lit. b GDPR, Art. 6 para. 1 lit. f GDPR.

3.7. Security Measures

In accordance with Art. 32 GDPR, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, we take appropriate technical and organizational measures to ensure a level of security appropriate to the risk.

The measures include, in particular, ensuring the confidentiality, integrity, and availability of data by controlling physical access to the data, as well as the access, input, transfer, ensuring availability, and their separation. Furthermore, we have established procedures that ensure the exercise of data subject rights, deletion of data, and reaction to data threats. Furthermore, we take the protection of personal data into account as early as the development or selection of hardware, software, and procedures, in accordance with the principle of data protection by design and by default (Art. 25 GDPR).

If IP addresses are processed by us or by our service providers and the processing of a full IP address is not required, the IP address is shortened (hereinafter referred to as “IP masking”). In this process, the last part of the IP address is removed or replaced by placeholders. The shortening of the IP address is intended to prevent or significantly complicate identification based on the IP address.

To protect data transmitted via our online services, we use SSL encryption, recognizable by the prefix “https://” in the address bar of your browser.

3.8. Rights of Data Subjects

You have the right to request confirmation as to whether relevant data is being processed and to information about this data as well as further information and a copy of the data in accordance with Art. 15 GDPR.

In accordance with Art. 16 GDPR, you have the right to request the completion of the data concerning you or the correction of incorrect data concerning you.

In accordance with Art. 17 GDPR, you have the right to request that relevant data be deleted immediately, or alternatively, in accordance with Art. 18 GDPR, to request a restriction of the processing of the data.

You have the right to request to receive the data concerning you that has been provided to us in accordance with Art. 20 GDPR and to demand its transmission to other controllers.

Furthermore, according to Art. 77 GDPR, you have the right to lodge a complaint with the competent supervisory authority.

3.9. Right of Withdrawal

You have the right to withdraw granted consents according to Art. 7 para. 3 GDPR with effect for the future.

3.10. Right to Object

You can object to the (future) processing of data based on Article 6 para. 1 lit. e or f at any time in accordance with Art. 21 GDPR. The objection can be made in particular against processing for the purposes of direct marketing. In the event of an objection, Planerio will no longer process the personal data unless Planerio can demonstrate compelling legitimate grounds for the processing which override the interests, rights, and freedoms of the data subject, or the processing serves the assertion, exercise, or defense of Planerio’s legal claims.

3.11. Deletion of Data

The data processed by us will be deleted or restricted in its processing in accordance with Art. 17 and 18 GDPR. Unless expressly stated within this privacy policy, the data stored by us will be deleted as soon as it is no longer required for its intended purpose and there are no statutory retention obligations to the contrary. If the data is not deleted because it is required for other and legally permissible purposes, its processing will be restricted. This means the data is blocked and not processed for other purposes. This applies, for example, to data that must be kept for labor, commercial, or tax law reasons or in cases where the processing of the data is necessary for the assertion, exercise, or defense of legal claims or for the protection of the rights of another natural or legal person.

According to legal requirements in Germany, retention occurs in particular for 10 years according to §§ 147 para. 1 AO, 257 para. 1 no. 1 and 4, para. 4 HGB (books, records, management reports, accounting vouchers, commercial books, documents relevant for taxation, etc.) and 6 years according to § 257 para. 1 no. 2 and 3, para. 4 HGB (commercial letters).

3.12. Contractual Services

We process the data of our contractual partners and interested parties as well as other clients, customers, or contractual partners (hereinafter each individually and collectively referred to as “contractual partners”) in accordance with Art. 6 para. 1 lit. b GDPR in order to provide our contractual or pre-contractual services to them. The data processed here, the nature, scope, purpose, and necessity of their processing, are determined by the underlying contractual relationship.

The processed data includes the master data of our contractual partners (e.g., names and addresses), contact details (e.g., email addresses and phone numbers) as well as contract data (e.g., services used, contract content, contractual communication, names of contact persons) and payment data (e.g., bank details, payment history).

We generally do not process special categories of personal data unless these are components of a commissioned or contractually agreed processing.

We process data required for the establishment and fulfillment of contractual services and point out the necessity of providing it, unless this is evident to the contractual partners. Disclosure to external persons or companies only takes place if it is necessary within the framework of a contract. When processing the data provided to us within the framework of an order, we act in accordance with the instructions of the clients and the legal requirements.

Within the framework of using our online services, we can store the IP address and the time of the respective user action. The storage is based on our legitimate interests, as well as the interests of the users in protection against misuse and other unauthorized use. A transfer of this data to third parties generally does not take place unless it is necessary to pursue our claims according to Art. 6 para. 1 lit. f GDPR or there is a legal obligation to do so according to Art. 6 para. 1 lit. c GDPR.

The deletion of the data takes place when the data is no longer required for the fulfillment of contractual or legal duties of care as well as handling any warranty and comparable obligations, whereby the necessity of retaining the data is reviewed every three years; otherwise, the statutory retention obligations apply.

4. Cooperation with Processors and Third Parties and Transfer to Third Countries

4.1. Cooperation with Processors and Third Parties

If we disclose data to other persons and companies (processors or third parties) within the scope of our processing, transmit it to them, or otherwise grant them access to the data, this only takes place on the basis of a legal permission (e.g., if a transmission of the data to third parties, such as to payment service providers, is required for contract fulfillment according to Art. 6 para. 1 lit. b GDPR), you have consented, a legal obligation provides for this, or on the basis of our legitimate interests (e.g., when using agents, web hosts, etc.).

If we commission third parties with the processing of data on the basis of a so-called “data processing agreement”, this is done in accordance with Art. 28 GDPR.

4.2. Transfers to Third Countries

If we process data in a third country (i.e., outside the European Union (EU) or the European Economic Area (EEA)) or if this happens within the framework of using third-party services or disclosure or transmission of data to third parties, this only takes place if it is done to fulfill our (pre-)contractual obligations, on the basis of your consent, due to a legal obligation, or on the basis of our legitimate interests. Subject to legal or contractual permissions, we process or have the data processed in a third country only if the special requirements of Art. 44 ff. GDPR are met. This means the processing takes place on the basis of an adequacy decision according to Art. 45 GDPR as well as in compliance with and implementation of appropriate guarantees according to Art. 46 GDPR, e.g., by concluding so-called “standard contractual clauses”.

5. Registration, Order Processing, and Use of Our Online Services

5.1. Registration

If you want to use the services offered via our online services, registration is required. The processed data includes, in particular, the login information (name, password, and an email address).

If you set up an account for another person and/or thereby transmit data of this person to us for processing, we must assume that the respective person is informed about this and agrees to it.

The collection of this data takes place to confirm the registration, to set up access, and to establish contact. The data processing is based on Art. 6 para. 1 sentence 1 lit. b GDPR, insofar as you are our direct contractual partner, or on Art. 6 para. 1 sentence 1 lit. f GDPR, if you carry out the registration as an employee or authorized representative of such a direct contractual partner (legitimate interest of Planerio).

Users can be informed by email about information relevant to their user account, such as technical changes. If users have terminated their user account, their data with regard to the user account will be deleted, subject to a statutory retention obligation. It is the responsibility of the users to secure their data upon termination before the end of the contract. We are entitled to irretrievably delete all user data stored during the term of the contract.

Within the framework of using our registration and login functions as well as the use of the user account, we store the IP address and the time of the respective user action. The storage is based on our legitimate interests, as well as those of the users in protection against misuse and other unauthorized use. A transfer of this data to third parties generally does not take place unless it is necessary to pursue our claims or there is a legal obligation to do so according to Art. 6 para. 1 lit. c GDPR. The IP addresses are anonymized or deleted after 7 days at the latest.

5.2. Order Processing

We process the data of our customers within the framework of the ordering processes to enable them to select and order the chosen products and services, as well as their payment and execution.

The processed data includes master data, communication data, contract data, payment data, and the persons affected by the processing include our customers, interested parties, and other business partners. The processing takes place for the purpose of providing contractual services within the framework of our online services.

The processing takes place on the basis of Art. 6 para. 1 lit. b (execution of ordering processes) and c (legally required archiving) GDPR. The information marked as required is necessary for the establishment and fulfillment of the contract. We disclose the data to third parties only within the framework of delivery, payment, or within the framework of legal permissions and obligations to legal advisors and authorities. The data is processed in third countries only if this is necessary for contract fulfillment (e.g., at the customer’s request for delivery or payment).

5.3. Use of Our Online Services

5.3.1. Web Application

If you use our online services after registration – whether free of charge or for a fee – you can post data on the platform, share it with your company or other users, adjust it, and communicate with other users.

If you transmit data of another person to us for processing when using our online services, we must assume that the respective person is informed about this and agrees to it.

This data is collected and processed to offer and bill the services offered within the framework of our online services, such as shift planning, time tracking, and payroll, i.e., to fulfill Planerio’s contractual obligations. The data processing is based on Art. 6 para. 1 sentence 1 lit. b GDPR, insofar as you are our direct contractual partner, or on Art. 6 para. 1 sentence 1 lit. f GDPR, if you carry out the registration as an employee or authorized representative of such a direct contractual partner (legitimate interest of Planerio).

5.3.2. Mobile App

Our application can also be obtained via special online platforms operated by other service providers (so-called “app stores”). In this context, the privacy policies of the respective app stores apply in addition to our privacy policy. This applies in particular with regard to the procedures used on the platforms for reach measurement and interest-based marketing as well as any costs.

Master and shift planning data (e.g., names, addresses, shifts, absences); contact details (e.g., email, phone numbers); contract data (e.g., subject matter of the contract, term, customer category); usage data (e.g., visited websites, interest in content, access times); meta/communication data (e.g., device information, IP addresses) are processed. Data subjects are customers and users. The purpose of the processing is the provision of contractual services and customer service. The processing is based on the legal bases of contract fulfillment and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b GDPR) and legitimate interests (Art. 6 para. 1 sentence 1 lit. f GDPR).

Apple App Store

App and software sales platform; service provider: Apple Inc., Infinite Loop, Cupertino, CA 95014, USA; website: https://www.apple.com/app-store/; privacy policy: .

Google Play

App and software sales platform; service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain

View, CA 94043, USA; website: https://play.google.com/store/apps; privacy policy: https://policies.google.com/privacy.

5.3.3. Special Information on Applications (Apps)

We process the data of the users of our application insofar as this is necessary to provide the application and its functionalities to the users, to monitor its security, and to be able to develop it further. We can also contact users in compliance with legal requirements if communication is necessary for purposes of administration or use of the application. Otherwise, we refer to the privacy information in this privacy policy with regard to the processing of user data.

The processing of data required for the provision of the application’s functionalities serves to fulfill contractual obligations. This also applies if the provision of the functions requires authorization from the users (e.g., sharing of device functions). If the processing of data is not required for the provision of the application’s functionalities but serves the security of the application or our business interests (e.g., collection of data for purposes of optimizing the application or security purposes), it takes place on the basis of our legitimate interests. If users are expressly asked for their consent to the processing of their data, the processing of the data covered by the consent takes place on the basis of the consent.

Master data (e.g., names, addresses), meta/communication data (e.g., device information, IP addresses), payment data (e.g., bank details, invoices, payment history), contract data (e.g., subject matter of the contract, term, customer category), location data (information on the geographical position of a device or a person) are processed.

Users (e.g., website visitors, users of online services) are affected by the processing. The processing takes place for the purpose of providing contractual services and customer service and is based on consent (Art. 6 para. 1 sentence 1 lit. a GDPR), contract fulfillment and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b GDPR), and legitimate interests (Art. 6 para. 1 sentence 1 lit. f GDPR).

5.3.4. Further Information on Processing Operations, Procedures, and Services

Commercial Use

We process the data of the users of our application, registered and any test users (hereinafter each individually and collectively referred to as “users”), in order to be able to provide our contractual services to them, as well as on the basis of legitimate interests in order to be able to ensure the security of our application and to develop it further. The required information is marked as such within the framework of the use, order, or comparable contract conclusion and can include the information required for service provision and any billing as well as contact information in order to be able to hold any consultations.

Device Permissions for Access to Functions and Data

The use of our application or its functionalities may require user permissions for access to certain functions of the devices used or to the data stored on the devices or accessible with the help of the devices. By default, these permissions must be granted by the users and can be withdrawn at any time in the settings of the respective devices. The exact procedure for controlling app permissions may depend on the user’s device and software. Users can contact us if they need explanation. We point out that the refusal or withdrawal of the respective permissions can affect the functionality of our application.

Processing of Stored Contacts

Within the framework of using our application, the contact information of persons (name, email address, phone number) stored in the contact directory of the device is processed. The use of the contact information requires an authorization from the users, which can be withdrawn at any time. The use of the contact information serves only to provide the respective functionality of our application, according to its description to the users, or its typical and expected mode of operation. Users are informed that the permission to process the contact information must be allowed and, in particular in the case of natural persons, requires their consent or a legal permission.

Processing of Location Data

Within the framework of using our application, the location data collected by the device used or otherwise entered by the users is processed. The use of the location data requires an authorization from the users, which can be withdrawn at any time. The use of the location data serves only to provide the respective functionality of our application, according to its description to the users, or its typical and expected mode of operation.

5.4. Function-Dependent Integrations

Depending on the functions chosen by the contractual partner, data exchange takes place with one or more of the following companies in order to be able to provide and continuously improve our services; the legal basis for the processing of the data is Art. 6 para. 1 sentence 1 lit. b GDPR. If the third-party providers mentioned under section 5.4 act for us as processors, the processing of order data takes place in accordance with Art. 28 GDPR. We have selected these third-party providers carefully and in accordance with the provisions of the GDPR.

Doctolib

Online appointment scheduling and management; service provider: Doctolib GmbH, Wilhelmstraße 118, Aufgang C, 10963 Berlin, Germany, parent company: Doctolib SAS, 32 rue de Monceau 75008 Paris, France; website: https://www.doctolib.de; privacy policy: https://www.doctolib.de/terms/agreement.

Personio

HR management and recruiting platform and services; Service provider: Personio GmbH, Rundfunkplatz 4, 80335 Munich, Germany; Website: https://personio.de/; Privacy Policy: https://www.personio.de/datenschutzerklaerung/.

SAP

Integrated standard business software product with functions in the area of personnel management and payroll; service provider: SAP Deutschland SE & Co. KG, Hasso-Plattner-Ring 7, 69190 Walldorf, Germany; website: https://www.sap.com/; privacy policy: https://www.sap.com/germany/about/legal/privacy.html.

5.5. Video Conferencing, Online Meetings, Webinars, and Screen Sharing

We use platforms and applications from other providers (hereinafter referred to as “conferencing platforms”) for the purpose of conducting video and audio conferences, webinars, and other types of video and audio meetings (hereinafter collectively referred to as “conference”). When selecting the conferencing platforms and their services, we observe the legal requirements.

Within the framework of participation in a conference, the conferencing platforms process the personal data of the participants mentioned below. The scope of processing depends on the one hand on which data is required within the framework of a specific conference (e.g., provision of access data or real names) and which optional information is provided by the participants. In addition to processing to conduct the conference, the data of the participants can also be processed by the conferencing platforms for security purposes or service optimization. The processed data includes personal data (first name, last name), contact information (email address, phone number), access data (access codes or passwords), profile pictures, information on professional position/function, the IP address of the internet access, information on the participants’ end devices, their operating system, the browser and its technical and language settings, information on the content-related communication processes, i.e., entries in chats as well as audio and video data, as well as the use of other available functions (e.g., surveys). Content of communications is encrypted to the extent technically provided by the conference providers. If the participants are registered as users with the conferencing platforms, then further data can be processed in accordance with the agreement with the respective conference provider.

If text entries, participation results (e.g., from surveys), as well as video or audio recordings are logged, this will be communicated transparently to the participants in advance and they will be asked for consent – if necessary.

Please refer to the privacy policies of the conferencing platforms for details on the processing of your data and choose the security and privacy settings that are optimal for you within the settings of the conferencing platforms. Please also ensure data and personality protection in the background of your recording for the duration of a video conference (e.g., by informing housemates, locking doors, and using, as far as technically possible, the function to blur the background). Links to the conference rooms as well as access data must not be passed on to unauthorized third parties.

If, in addition to the conferencing platforms, we also process the data of the users and ask the users for their consent to the use of the conferencing platforms or certain functions (e.g., consent to a recording of conferences), the legal basis for the processing is this consent. Furthermore, our processing may be necessary to fulfill our contractual obligations (e.g., in participant lists, in the case of processing conversation results, etc.). Otherwise, the data of the users is processed on the basis of our legitimate interests in efficient and secure communication with our communication partners.

Master data (e.g., names, addresses); contact details (e.g., email, phone numbers), content data (e.g., entries in online forms), usage data (e.g., visited websites, interest in content, access times), meta/communication data (e.g., device information, IP addresses) are processed. Communication partners, users (e.g., website visitors, users of online services) are affected. The processing takes place for the purpose of providing contractual services and customer service, contact requests and communication, office and organizational procedures and is based on the legal bases of consent (Art. 6 para. 1 sentence 1 lit. a GDPR), contract fulfillment and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b GDPR), and legitimate interests (Art. 6 para. 1 sentence 1 lit. f GDPR).

Microsoft Teams

Messenger and conferencing software; service provider: Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland, parent company:

Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399 USA; website: https://products.office.com; privacy policy: https://www.microsoft.com/en-us/privacy/privacystatement, security information: https://www.microsoft.com/en-us/trust-center; standard contractual clauses (guarantee of data protection level for processing in third countries): https://www.microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA.

Furthermore, the parent company Microsoft Corporation, as a US company, is certified under the EU-US Data Privacy Framework. There is an adequacy decision pursuant to Art. 45 GDPR, so that a transfer of personal data may also take place without further guarantees or additional measures.

5.6. Chatbots and Chat Functions

We offer online chats and chatbot functions as a communication option (collectively referred to as “chat services”). A chat is an online conversation conducted with a certain degree of timeliness. A chatbot is software that answers users’ questions or informs them via messages. If you use our chat functions, we can process your personal data.

If you use our chat services within an online platform, your identification number within the respective platform is additionally stored. We can also collect information about which users interact with our chat services and when. Furthermore, we store the content of your conversations via the chat services and log registration and consent processes in order to be able to prove these according to legal requirements.

We point out to users that the respective platform provider can find out that and when users communicate with our chat services and can collect technical information about the device used by the users and, depending on the settings of their device, also location information (so-called metadata) for purposes of optimizing the respective services and for security purposes. Likewise, the metadata of communication via chat services (i.e., for example, the information who communicated with whom) could be used by the respective platform providers in accordance with their provisions, to which we refer for further information, for purposes of marketing or for displaying advertisements tailored to users.

If users agree to a chatbot to activate information with regular messages, they have the option to unsubscribe from the information for the future at any time. The chatbot informs users how and with which terms they can unsubscribe from the messages. By unsubscribing from the chatbot messages, the user’s data is deleted from the directory of message recipients.

We use the aforementioned information to operate our chat services, e.g., to address users personally, to answer their inquiries, to transmit any requested content, and also to improve our chat services (e.g., to “teach” chatbots answers to frequently asked questions or to recognize unanswered inquiries).

We use the chat services on the basis of consent if we have previously obtained permission from the users to process their data within the framework of our chat services (this applies to cases in which users are asked for consent, e.g., so that a chatbot sends them regular messages). If we use chat services to answer user inquiries about our services or our company, this is done for contractual and pre-contractual communication. Otherwise, we use chat services on the basis of our legitimate interests in optimizing the chat services, their economic efficiency, and an increase in the positive user experience.

You can withdraw a granted consent at any time or object to the processing of your data within the framework of our chat services.

Contact details (e.g., email, phone numbers); content data (e.g., entries in online forms), usage data (e.g., visited websites, interest in content, access times), meta/communication data (e.g., device information, IP addresses) are processed. Our communication partners are affected. The purpose of the processing is to respond to contact requests and communication, direct marketing (e.g., by email or post). The processing is based on the legal bases of consent (Art. 6 para. 1 sentence 1 lit. a GDPR), contract fulfillment and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b GDPR), and legitimate interests (Art. 6 para. 1 sentence 1 lit. f GDPR).

Pipedrive

We use the CRM system Pipedrive (https://www.pipedrive.com/) from the provider Pipedrive OÜ on the basis of our legitimate interests according to Art. 6 para. 1 sentence 1 lit. f GDPR (efficient and fast processing of user inquiries, existing customer management, new customer business), a private limited company established under the laws of the Republic of Estonia, with the address Paldiski mnt 80, Tallinn, 10617, Estonia, registered in the Estonian Commercial Register under the code 11958539, and a subsidiary of Pipedrive US. You can access Pipedrive’s privacy policy here: https://www.pipedrive.com/en/privacy.

Furthermore, the parent company Pipedrive Inc., as a US company, is certified under the EU-US Data Privacy Framework. There is an adequacy decision pursuant to Art. 45 GDPR, so that a transfer of personal data may also take place without further guarantees or additional measures.

5.7. Push Notifications

With the consent of users, we may send users so-called “push notifications.” These are messages that are displayed on users’ screens, devices, or in browsers, even if our online service is not currently being actively used.

To register for push notifications, users must confirm their browser’s or device’s request to receive push notifications. This consent process is documented and stored. Storage is necessary to recognize whether users have consented to receive push notifications and to be able to prove consent. For these purposes, a pseudonymous identifier of the browser (so-called “push token”) or the device ID of a terminal device is stored.

Push notifications may be necessary for the fulfillment of contractual obligations (e.g., technical and organizational information relevant to the use of our online offer) and are otherwise sent on the basis of user consent, unless specifically mentioned below. Users can change the receipt of push notifications at any time using the notification settings of their respective browsers or devices.

Usage data (e.g., visited websites, interest in content, access times) is processed. The processing is carried out to provide contractual services and customer service, reach measurement (e.g., access statistics, recognition of returning visitors) and is based on consent (Art. 6(1)(a) GDPR), contract fulfillment, and pre-contractual inquiries (Art. 6(1)(b) GDPR).

We evaluate push notifications statistically and can thus recognize if and when push notifications were displayed and clicked. This information is used for the technical improvement of our push notifications based on technical data or target groups and their retrieval behavior or retrieval times. This analysis also includes determining whether push notifications are opened, when they are opened, and whether users interact with their content or buttons. Although this information can be assigned to individual push notification recipients for technical reasons, it is neither our endeavor nor, if used, that of the push notification service provider to observe individual users. Rather, the analytics serve us to recognize the usage habits of our users and to adapt our push notifications to them or to send different push notifications according to the interests of our users. The evaluation of push notifications and conversion tracking are carried out on the basis of express user consent, which is given by agreeing to receive push notifications. Users can object to the analysis and conversion tracking by unsubscribing from push notifications. A separate revocation of the analysis and conversion tracking is unfortunately not possible.

OneSignal

Sending and management of push notifications; Service provider: OneSignal, Inc., 2850 S Delaware St Suite 201, San Mateo, CA 94403, USA; Website: https://onesignal.com; Privacy Policy: https://onesignal.com/privacy_policy; Standard Contractual Clauses (guaranteeing the level of data protection for processing in third countries): are concluded with the provider.

This US company is also certified under the EU-US Data Privacy Framework. There is an adequacy decision pursuant to Art. 45 GDPR, so that a transfer of personal data may also take place without further guarantees or additional measures.

5.8. Guided Tours/Guides, Usage Profiles, User Feedback, and Communication

We use Pendo to provide guided tours/guides, to create usage profiles for the demand-based design of the software, to collect user feedback, and for communication to users. Data processing is based on our legitimate interests according to Art. 6(1)(f) GDPR, with a right to object in the third-party provider area. Service provider is Pendo Inc., 418 South Dawson St., Raleigh, NC 27601, USA. Purposes/legitimate interests: conducting guided tours/guides through the software during the software implementation phase and in customer service, aggregated analysis of usage behavior within the software, collection of customer feedback, e.g., within the framework of NPS (Net Promoter Scores) for product development, in-app communication to users regarding new releases, for example; data (categories): master data (e.g., customer ID, user ID, user role, language), content data (e.g., text entries), contract data (e.g., subject matter of the contract), usage and metadata (e.g., as part of the evaluation of usage rates or conversion tracking), progress status in the tour/guide (also within the framework of cookies); data subjects: all users; suitable or appropriate guarantees: EU Standard Contractual Clauses; further information: https://www.pendo.io/privacypolicy/.

5.9. Processing of Location Data

As part of the use of our application, location data collected by the device used or otherwise entered by users is processed. The use of location data requires user consent, which can be revoked at any time. The use of location data serves only to provide the respective functionality of our application, in accordance with its description to users, or its typical and expected mode of operation.

5.10. Service and Consulting Services

We process our customers’ data as part of our contractual services, which include software implementation, conceptual and strategic consulting, software and design development/consulting or care, implementation of campaigns and processes/handling, server administration, data analysis/consulting services, and training services.

In this context, we process master data (e.g., customer master data, such as names or addresses), contact data (e.g., email, telephone numbers), content data (e.g., text entries), contract data (e.g., subject matter of the contract, term), payment data (e.g., bank details, payment history), usage and metadata (e.g., as part of the evaluation of usage rates or conversion tracking). We generally do not process special categories of personal data unless these are components of a commissioned processing. Data subjects include our customers, interested parties, as well as their customers, users, website visitors or employees, and third parties. The purpose of the processing is the provision of contractual services, billing, and our customer service. The legal basis for processing arises from Art. 6(1)(b) GDPR (contractual services), Art. 6(1)(f) GDPR (analysis, statistics, optimization, security measures). We process data that is required for the establishment and fulfillment of contractual services and point out the necessity of providing it. Disclosure to external parties only takes place if it is necessary within the scope of an order. When processing data provided to us as part of an order, we act in accordance with the instructions of the client and the legal requirements of a data processing agreement pursuant to Art. 28 GDPR and process the data for no purposes other than those specified in the order.

We delete the data after the expiry of statutory warranty and comparable obligations. The necessity of keeping the data is reviewed every three years; in the case of statutory archiving obligations, deletion takes place after their expiry (6 years, pursuant to Section 257(1) HGB, 10 years, pursuant to Section 147(1) AO). In the case of data disclosed to us by the client as part of an order, we delete the data in accordance with the specifications of the order, generally after the end of the order.

5.11. Administration, Financial Accounting, Organization, Contact Management

5.11.1. General

We process data as part of administrative tasks as well as the organization of our operations, financial accounting, compliance with legal obligations, such as archiving, for purposes of organization, administration, planning, and provision of our services. In doing so, we use services, platforms, and software from other providers (hereinafter referred to as “third-party providers”). When selecting third-party providers and their services, we comply with legal requirements.

In general, we process the same data that we process as part of the provision of our (pre-)contractual services. If we ask users for their consent to the use of third-party providers, the legal basis for the processing of data is consent. Furthermore, their use may be a component of our (pre-)contractual services, provided that the use of third-party providers was agreed upon in this context. Otherwise, user data is processed on the basis of our legitimate interests (i.e., interest in efficient, economical, and recipient-friendly services). In this context, we would also like to refer you to the information on the use of cookies in this privacy policy.

Customers, interested parties, business partners, and website visitors are affected by the processing. The purpose and our interest in the processing lie in administration, financial accounting, office organization, archiving of data, i.e., tasks that serve to maintain our business activities, perform our tasks, and provide our services.

The deletion of data with regard to contractual services and contractual communication corresponds to the information specified for these processing activities.

In this context, personal data may be processed and stored on the servers of third-party providers. Various data that we process in accordance with this privacy policy may be affected by this. This data may include, in particular, master data and contact data of users, data on transactions, contracts, other processes, and their content.

If users are referred to third-party providers or their software or platforms as part of communication, business, or other relationships with us, the third-party providers may process usage data and metadata for security purposes, for service optimization, or for marketing purposes. We therefore ask you to observe the privacy notices of the respective third-party providers.

We disclose or transmit data to the tax authorities, consultants, such as tax advisors or auditors, as well as other fee offices and payment service providers.

Furthermore, on the basis of our business interests, we store information on suppliers, organizers, and other business partners, e.g., for the purpose of later contact. We generally store this mostly company-related data permanently.

5.11.2. Further Information on Processing Operations, Procedures, and Services

Billomat

For bookkeeping purposes, we use the cloud-based accounting software from Billomat GmbH & Co. KG, Lorenzer Str. 31, 90402 Nuremberg (“Billomat”). Billomat processes incoming and outgoing invoices and, if applicable, also our company’s bank movements in order to automatically record invoices, match them to transactions, and create financial accounting from this in a semi-automated process. If personal data is also processed in this context, the processing is carried out in accordance with Art. 6(1)(f) GDPR on the basis of our legitimate interest in an efficient organization and documentation of our business transactions. Further information on Billomat, the automated processing of data, and the data protection provisions can be found at https://www.billomat.com/datenschutz/.

Calendly

Online appointment scheduling and appointment management; Service provider: Calendly LLC., 271 17th St NW, Ste 1000, Atlanta, Georgia, 30363, USA; Website: https://calendly.com/; Privacy Policy: https://calendly.com/pages/privacy; Data processing agreement: https://calendly.com/dpa; Standard Contractual Clauses (guaranteeing the level of data protection for processing in third countries): https://calendly.com/dpa.

Confluence

Software for the creation and administration of wiki & knowledge platforms; Service provider: Atlassian Inc. (San Francisco, Harrison Street Location), 1098 Harrison Street, San Francisco, California 94103, USA; Website: https://www.atlassian.com/software/confluence; Privacy Policy: https://www.atlassian.com/legal/privacy-policy; Standard Contractual Clauses (guaranteeing the level of data protection for processing in third countries): part of the data processing agreement; Further information: Data Transfer Impact Assessment: https://www.atlassian.com/legal/data-transfer-impact-assessment.

The US company Atlassian Inc. is also certified under the EU-US Data Privacy Framework. There is an adequacy decision pursuant to Art. 45 GDPR, so that a transfer of personal data may also take place without further guarantees or additional measures.

Jira

Web application for bug tracking, troubleshooting, and operational project management; Service provider: Atlassian Inc. (San Francisco, Harrison Street Location), 1098 Harrison Street, San Francisco, California 94103, USA; Website: https://www.atlassian.com/software/jira; Privacy Policy: https://www.atlassian.com/legal/privacy-policy; Data processing agreement: https://www.atlassian.com/legal/data-processing-addendum; Standard Contractual Clauses (guaranteeing the level of data protection for processing in third countries): inclusion in the data processing agreement; Further information: Data Transfer Impact Assessment: https://www.atlassian.com/legal/data-transfer-impact-assessment.

The US company Atlassian Inc. is also certified under the EU-US Data Privacy Framework. There is an adequacy decision pursuant to Art. 45 GDPR, so that a transfer of personal data may also take place without further guarantees or additional measures.

Kombo

We use the integration service provider kombo.dev, a service of Kombo Technologies GmbH, Kottbusser Damm 25-26, 10967 Berlin (hereinafter “Kombo”). We use Kombo to integrate different databases and web applications. Kombo is a web service that automatically links actions between different databases and web applications and synchronizes their applications with each other. Kombo automates our processing operations and ensures different workflows for efficient data processing. The described data processing operations are carried out in accordance with Art. 6(1)(f) GDPR on the basis of our legitimate interests in the efficient design of our work processes. Further information on data use by Kombo can be found in the Kombo privacy policy at https://www.kombo.dev/privacy-policy.

monday.com

Project management – organization and management of teams, groups, workflows, projects, and processes; Service provider: monday.com ltd, 6 Yitzhak Sadeh Street, Tel Aviv 6777506, Israel; Website: https://monday.com/lang/de/; Privacy Policy: https://monday.com/l/de/privatsphaere/datenschutzerklarung/; Data processing agreement: https://monday.com/l/de/privatsphaere/dpa/; Standard Contractual Clauses (guaranteeing the level of data protection for processing in third countries): https://monday.com/l/de/privatsphaere/standardvertragsbedingungen-fuer-kunden-scc-datenverantwortlicher-zu-datenverarbeiter/ (Controller to Processor), https://monday.com/l/de/privatsphaere/standardvertragsbedingungen-fuer-kunden-scc-datenverarbeiter-zu-datenverarbeiter/ (Processor to Processor).

n8n

We use the integration service provider n8n.io, a service of n8n GmbH, Borsigstr. 27, 10115 Berlin (hereinafter “n8n”). We use n8n to integrate different databases and web tools. n8n is a web service that automatically links actions between different tools and synchronizes their applications with each other. n8n automates our processing operations and ensures different workflows for efficient data processing. The described data processing operations are carried out in accordance with Art. 6(1)(f) GDPR on the basis of our legitimate interests in the efficient design of our work processes. Further information on data use by n8n can be found in the n8n privacy policy at https://n8n.io/legal/#privacy.

PandaDoc

Digital signatures and signing procedures for documents; Service provider: PandaDoc, Inc., 3739 Balboa St. #1083, San Francisco, CA 94121, USA; Website: https://www.pandadoc.com/de/; Privacy Policy: https://www.pandadoc.com/de/privacy-notice/; Further information: https://www.pandadoc.com/gdpr/.

This US company is also certified under the EU-US Data Privacy Framework. There is an adequacy decision pursuant to Art. 45 GDPR, so that a transfer of personal data may also take place without further guarantees or additional measures.

Pipedrive

We use the CRM system Pipedrive from the provider Pipedrive OÜ on the basis of our legitimate interests (efficient and fast processing of user inquiries, existing customer management, new customer business), a private limited company established under the laws of the Republic of Estonia, with the address Paldiski mnt 80, Tallinn, 10617, Estonia, registered in the Estonian Commercial Register under code 11958539, and a subsidiary of Pipedrive US. You can access Pipedrive’s privacy policy here: https://www.pipedrive.com/en/privacy. Data processing agreement: https://www.pipedrive.com/en/privacy#data-controller-and-data-processor

Furthermore, the parent company Pipedrive Inc., as a US company, is certified under the EU-US Data Privacy Framework. There is an adequacy decision pursuant to Art. 45 GDPR, so that a transfer of personal data may also take place without further guarantees or additional measures.

Salesforce

We use the CRM system Salesforce from the provider salesforce.com Germany GmbH (https://www.salesforce.com/), Erika-Mann-Str. 31, 80636 Munich, Germany on the basis of our legitimate interests (efficient and fast processing of user inquiries, existing customer management, new customer business), a subsidiary of Salesforce, Inc. You can access Salesforce’s privacy policy here: https://www.salesforce.com/company/legal/privacy/.

Furthermore, the parent company Salesforce, Inc., as a US company, is certified under the EU-US Data Privacy Framework. There is an adequacy decision pursuant to Art. 45 GDPR, so that a transfer of personal data may also take place without further guarantees or additional measures.

5.12. Plugins and Embedded Functions and Content

5.12.1. General Information on Plugins and Embedded Functions and Content

We integrate functional and content elements into our online offer that are obtained from the servers of their respective providers (hereinafter referred to as “third-party providers”). These can be, for example, graphics, videos, or city maps (hereinafter collectively referred to as “content”).

Integration always requires that the third-party providers of this content process the IP address of the users, as they could not send the content to their browser without the IP address. The IP address is therefore required for the display of this content or functions. We strive to use only such content whose respective providers use the IP address solely for the delivery of the content. Third-party providers may also use so-called pixel tags (invisible graphics, also referred to as “web beacons”) for statistical or marketing purposes. Through the “pixel tags,” information such as visitor traffic on the pages of this website can be evaluated. The pseudonymous information may also be stored in cookies on the user’s device and may contain, among other things, technical information about the browser and operating system, referring websites, time of visit, and other information about the use of our online offer, as well as be linked to such information from other sources.

Notes on legal bases: If we ask users for their consent to the use of third-party providers, the legal basis for the processing of data is consent. Otherwise, user data is processed on the basis of our legitimate interests (i.e., interest in efficient, economical, and recipient-friendly services). In this context, we would also like to refer you to the information on the use of cookies in this privacy policy.

Usage data (e.g., visited websites, interest in content, access times), meta/communication data (e.g., device information, IP addresses), master data (e.g., names, addresses), contact data (e.g., email, telephone numbers), content data (e.g., entries in online forms) are processed. Data subjects of the data processing are users (e.g., website visitors, users of online services). The processing takes place for the purpose of providing our online offer and user-friendliness, providing contractual services and customer service, profiles with user-related information (creating user profiles) and is based on consent (Art. 6(1)(a) GDPR), contract fulfillment and pre-contractual inquiries (Art. 6(1)(b) GDPR), legitimate interests (Art. 6(1)(f) GDPR).

5.12.2. Further Information on Processing Operations, Procedures, and Services

Integration of third-party software, scripts, or frameworks (e.g., jQuery)

We integrate software into our online offer that we retrieve from servers of other providers (e.g., function libraries that we use for the purpose of display or user-friendliness of our online offer). In doing so, the respective providers collect the IP address of the users and can process it for the purpose of transmitting the software to the users’ browser as well as for security purposes, as well as for the evaluation and optimization of their offer.

Google Fonts

Obtaining fonts (“Google Fonts”) from the provider Google for the purpose of technically secure, maintenance-free, and efficient use of fonts with regard to up-to-dateness and loading times, their uniform display, and consideration of possible licensing restrictions. Google is informed of the user’s IP address so that Google can provide the fonts in the user’s browser. In addition, technical data (language settings, screen resolution, operating system, hardware used) is transmitted, which is required for the provision of the fonts depending on the devices used and the technical environment. ; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; Website: https://fonts.google.com/; Privacy Policy: https://policies.google.com/privacy.

The parent company Google LLC is certified as a US company under the EU-US Data Privacy Framework. An adequacy decision pursuant to Art. 45 GDPR is therefore in place, meaning that a transfer of personal data may take place without further guarantees or additional measures.

Google Maps

We integrate the maps of the service “Google Maps” from the provider Google. The processed data may include, in particular, IP addresses and location data of the users, which, however, are not collected without their consent (usually carried out within the settings of their mobile devices); Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; Website: https://cloud.google.com/maps-platform; Privacy Policy: https://policies.google.com/privacy; Objection option (Opt-Out): Opt-Out plugin: https://tools.google.com/dlpage/gaoptout, settings for the display of advertisements: https://adssettings.google.com/authenticated.

The parent company Google LLC is certified as a US company under the EU-US Data Privacy Framework. An adequacy decision pursuant to Art. 45 GDPR is therefore in place, meaning that a transfer of personal data may take place without further guarantees or additional measures.

Vimeo

Video content; Service provider: Vimeo Inc., Attention: Legal Department, 555 West 18th Street New York, New York 10011, USA; Website: https://vimeo.com; Privacy Policy: https://vimeo.com/privacy; Objection option (Opt-Out): We point out that Vimeo can use Google Analytics and refer to the privacy policy (https://policies.google.com/privacy) as well as the opt-out options for Google Analytics (https://tools.google.com/dlpage/gaoptout) or Google’s settings for data use for marketing purposes (https://adssettings.google.com/).

YouTube Videos

Video content; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; Website: https://www.youtube.com; Privacy Policy: https://policies.google.com/privacy; Objection option (Opt-Out): Opt-Out plugin: https://tools.google.com/dlpage/gaoptout, settings for the display of advertisements: https://adssettings.google.com/authenticated.

The parent company Google LLC is certified as a US company under the EU-US Data Privacy Framework. An adequacy decision pursuant to Art. 45 GDPR is therefore in place, meaning that a transfer of personal data may take place without further guarantees or additional measures.

5.13. Business Analytics and Market Research

In order to operate our business economically and to be able to recognize market trends, wishes of contractual partners and users, we analyze the data available to us on business transactions, contracts, inquiries, etc. We process master data, communication data, contract data, payment data, usage data, metadata on the basis of Art. 6(1)(f) GDPR, whereby the data subjects include contractual partners, interested parties, customers, visitors, and users of our online offer.

The analyses are carried out for the purpose of business analytics, marketing, and market research. In doing so, we can take into account the profiles of registered users with information, e.g., on the services they have used. The analyses serve us to increase user-friendliness, optimize our offer, and improve business efficiency. The analyses serve us alone and are not disclosed externally, unless they are anonymous analyses with aggregated values.

5.14. Surveys and Inquiries

The surveys and inquiries conducted by us (hereinafter “surveys”) are evaluated anonymously. Personal data is only processed to the extent that this is necessary for the provision and technical implementation of the surveys (e.g., processing the IP address to display the survey in the user’s browser or to enable the survey to be resumed using a temporary cookie (session cookie)) or if users have consented.

If we ask participants for consent to the processing of their data, this is the legal basis for processing (Art. 6(1)(a) GDPR), otherwise the processing of participants’ data is based on our legitimate interests (Art. 6(1)(f) GDPR) in conducting an objective survey.

Contact data (e.g., email, telephone numbers), content data (e.g., entries in online forms), usage data (e.g., visited websites, interest in content, access times), meta/communication data (e.g., device information, IP addresses) are processed.

All our communication partners who participate in the survey or inquiry are affected. The purpose of the processing consists in contact requests and communication, direct marketing (e.g., by email or post).

6. Applicants and Application Procedures

6.1. Privacy Notices in the Application Procedure

We process applicant data only for the purpose and within the scope of the application procedure in accordance with legal requirements. The processing of applicant data is carried out to fulfill our (pre-)contractual obligations within the scope of the application procedure within the meaning of Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR if data processing becomes necessary for us, e.g., within the scope of legal proceedings (in Germany, Section 26 BDSG also applies). The application procedure requires that applicants provide us with applicant data. The necessary applicant data are marked if we offer an online form, otherwise they result from the job descriptions and generally include personal details, postal and contact addresses, and the documents belonging to the application, such as cover letter, CV, and certificates. In addition, applicants can voluntarily provide us with additional information. By submitting the application to us, applicants agree to the processing of their data for the purposes of the application procedure in accordance with the type and scope set out in this privacy policy. Insofar as special categories of personal data within the meaning of Art. 9(1) GDPR are voluntarily provided as part of the application procedure, their processing is additionally carried out according to Art. 9(2)(b) GDPR (e.g., health data, such as severe disability status or ethnic origin). Insofar as special categories of personal data within the meaning of Art. 9(1) GDPR are requested from applicants as part of the application procedure, their processing is additionally carried out according to Art. 9(2)(a) GDPR (e.g., health data if these are required for the exercise of the profession). If provided, applicants can submit their applications to us using an online form on our website. The data is transmitted to us in encrypted form according to the state of the art.

Furthermore, applicants can submit their applications to us via email. However, we ask you to note that emails are generally not sent in encrypted form and applicants must ensure encryption themselves. We can therefore take no responsibility for the transmission path of the application between the sender and the receipt on our server and therefore recommend using an online form or postal dispatch. Instead of applying via the online form and email, applicants still have the option of sending us their application by post. The data provided by applicants can be further processed by us for the purposes of the employment relationship in the event of a successful application. Otherwise, if the application for a job offer is not successful, the applicant’s data will be deleted. Applicant data will also be deleted if an application is withdrawn, which applicants are entitled to do at any time. Deletion takes place, subject to a justified revocation by the applicant, after the expiry of a period of six months so that we can answer any follow-up questions about the application and satisfy our obligations to provide evidence under the Equal Treatment Act. Invoices for any travel expense reimbursement are archived in accordance with tax law requirements.

6.2. Talent Pool

As part of the application, we offer applicants the opportunity to be included in our “talent pool” for a period of two years on the basis of consent within the meaning of Art. 6(1)(b) and Art. 7 GDPR. The application documents in the talent pool are processed solely within the scope of future job advertisements and the search for employees and are destroyed at the latest after the expiry of the above-mentioned period. Applicants are informed that their consent to inclusion in the talent pool is voluntary, has no influence on the current application procedure, and that they can revoke this consent at any time for the future as well as declare an objection within the meaning of Art. 21 GDPR.

6.3. Further Information on Processing Operations, Procedures, and Services

Stepstone

Recruiting platform and services; Service provider: StepStone Deutschland GmbH, Völklinger Straße 1, 40219 Düsseldorf, Germany; Website: https://www.stepstone.de; Privacy Policy: https://www.stepstone.de/Ueber-StepStone/Rechtliche-Hinweise/datenschutzerklaerung/.

Indeed

Recruiting platform and services; Service provider: Indeed Ireland Operations Limited, 124 St. Stephen’s Green, Dublin 2, Ireland; Website: https://indeed.com/; Privacy Policy: https://de.indeed.com/legal?#privacypolicy.

JOIN

Recruiting platform and services; Service provider: JOIN Solutions GmbH, Schönhauser Allee 36, 10435 Berlin, Germany; Website: https://join.com/de/; Privacy Policy: https://join.com/de/datenschutz/.

Personio

HR management and recruiting platform and services; Service provider: Personio GmbH, Rundfunkplatz 4, 80335 Munich, Germany; Website: https://personio.de/; Privacy Policy: https://www.personio.de/datenschutzerklaerung/.

7. Hosting

7.1. General Information on Hosting

The hosting services used by us serve to provide the following services: infrastructure and platform services, computing capacity, storage space and database services, security services, and technical maintenance services that we use for the purpose of operating this online offer.

In this context, we, or our hosting provider, process master data, contact data, content data, contract data, usage data, meta and communication data of customers, interested parties, and visitors to this online offer on the basis of our legitimate interests in an efficient and secure provision of this online offer pursuant to Art. 6(1)(f) GDPR in conjunction with Art. 28 GDPR (conclusion of a data processing agreement).

7.2. Collection of Access Data and Log Files

We, or our hosting provider, collect data on every access to the server on which this service is located (so-called server log files) on the basis of our legitimate interests within the meaning of Art. 6(1)(f) GDPR. The access data includes the name of the retrieved website, file, date and time of retrieval, amount of data transferred, report on successful retrieval, browser type and version, the user’s operating system, referrer URL (the previously visited page), IP address, and the requesting provider.

Log file information is stored for security reasons (e.g., to investigate acts of abuse or fraud) for a maximum duration of 7 days and then deleted. Data whose further storage is required for evidentiary purposes is excluded from deletion until the final clarification of the respective incident.

7.3. Further Information on Processing Operations, Procedures, and Services

Amazon Web Services (AWS)

Services in the field of providing information technology infrastructure and related services (e.g., storage space and/or computing capacities); Service provider: Amazon Web Services, Inc., 410 Terry Avenue North, Seattle WA 98109, USA; Website: https://aws.amazon.com/de/; Privacy Policy: https://aws.amazon.com/de/privacy/?nc1=f_pr; Data processing agreement: https://d1.awsstatic.com/legal/aws-gdpr/AWS_GDPR_DPA.pdf; Standard Contractual Clauses (guaranteeing the level of data protection for processing in third countries): https://aws.amazon.com/de/service-terms/.

This US company is also certified under the EU-US Data Privacy Framework. There is an adequacy decision pursuant to Art. 45 GDPR, so that a transfer of personal data may also take place without further guarantees or additional measures.

Hetzner

Services in the field of providing information technology infrastructure and related services (e.g., storage space and/or computing capacities); Service provider: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany; Website: https://www.hetzner.com; Privacy Policy: https://www.hetzner.com/de/rechtliches/datenschutz; Data processing agreement: https://docs.hetzner.com/de/general/general-terms-and-conditions/data-privacy-faq/.

Microsoft Cloud Services

Cloud storage, cloud infrastructure services, and cloud-based application software; Service provider: Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland, parent company: Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399 USA; Website: https://microsoft.com/de-de; Privacy Policy: https://privacy.microsoft.com/de-de/privacystatement, Security notices: https://www.microsoft.com/de-de/trustcenter; Data processing agreement: https://www.microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA; Standard Contractual Clauses (guaranteeing the level of data protection for processing in third countries): https://www.microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA.

Furthermore, the parent company Microsoft Corporation, as a US company, is certified under the EU-US Data Privacy Framework. There is an adequacy decision pursuant to Art. 45 GDPR, so that a transfer of personal data may also take place without further guarantees or additional measures.

8. Blog, Comments, and Posts

8.1. Comments and Posts

When users leave comments or other posts, their IP addresses may be stored for 7 days on the basis of our legitimate interests within the meaning of Art. 6(1)(f) GDPR. This is done for our security in case someone leaves illegal content in comments and posts (insults, prohibited political propaganda, etc.). In this case, we ourselves can be prosecuted for the comment or post and are therefore interested in the identity of the author.

Furthermore, we reserve the right to process user information for the purpose of spam detection on the basis of our legitimate interests pursuant to Art. 6(1)(f) GDPR.

The data provided within the scope of comments and posts will be stored by us permanently until the user objects.

8.2. Retrieval of Emojis and Smilies

Within our WordPress blog, graphic emojis (or smilies), i.e., small graphic files that express feelings, can be used, which are obtained from external servers. In doing so, the providers of the servers collect the IP addresses of the users. This is necessary so that the emoji files can be transmitted to the users’ browsers. The emoji service is offered by Automattic Inc., 60 29th Street #343, San Francisco, CA 94110, USA. Privacy notices from Automattic: https://automattic.com/privacy/. The server domains used are s.w.org and twemoji.maxcdn.com, which to our knowledge are so-called content delivery networks, i.e., servers that serve only for the fast and secure transmission of files and the personal data of users are deleted after transmission.

This US company is also certified under the EU-US Data Privacy Framework. There is an adequacy decision pursuant to Art. 45 GDPR, so that a transfer of personal data may also take place without further guarantees or additional measures.

9. Contacting Us and Customer Relationship Management (CRM)

9.1. General Information on Contacting Us and CRM

When contacting us (e.g., via contact form, email, telephone, or via social media) as well as within the scope of existing user and business relationships, the information of the inquiring persons is processed insofar as this is necessary to answer the contact inquiries and any requested measures.

Answering contact inquiries and managing contact and inquiry data within the scope of contractual or pre-contractual relationships is carried out to fulfill our contractual obligations or to answer (pre-)contractual inquiries and otherwise on the basis of legitimate interests in answering inquiries and maintaining user or business relationships.

Master data (e.g., names, addresses); contact data (e.g., email, telephone numbers); content data (e.g., entries in online forms) are processed. All our communication partners who use these channels are affected. The purpose of the processing consists in answering contact inquiries and communication, providing contractual services and customer service.

The processing is based on the legal grounds of contract fulfillment and pre-contractual inquiries (Art. 6(1)(b) GDPR), legitimate interests (Art. 6(1)(f) GDPR), and legal obligation (Art. 6(1)(c) GDPR).

9.2. Further Information on Processing Operations, Procedures, and Services

Contact Form

When users contact us via our contact form, email, or other communication channels, we process the data provided to us in this context to process the stated concern. For this purpose, we process personal data within the scope of pre-contractual and contractual business relationships, insofar as this is necessary for their fulfillment and otherwise on the basis of our legitimate interests as well as the interests of the communication partners in answering the concerns and our legal storage obligations.

reCAPTCHA

We integrate the “reCAPTCHA” function to be able to recognize whether entries (e.g., in online forms) are made by humans and not by automatically acting machines (so-called “bots”). The processed data may include IP addresses, information on operating systems, devices or browsers used, language settings, location, mouse movements, keystrokes, time spent on websites, previously visited websites, interactions with ReCaptcha on other websites, possibly cookies, and results of manual recognition processes (e.g., answering questions asked or selecting objects in images). Data processing is carried out on the basis of our legitimate interest in protecting our online offer from abusive automated crawling and spam; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; Website: https://www.google.com/recaptcha/; Privacy Policy:

https://policies.google.com/privacy; Objection option (Opt-Out): Opt-Out plugin: https://tools.google.com/dlpage/gaoptout?hl=de, settings for the display of advertisements: https://adssettings.google.com/authenticated.

The parent company Google LLC is certified as a US company under the EU-US Data Privacy Framework. An adequacy decision pursuant to Art. 45 GDPR is therefore in place, meaning that a transfer of personal data may take place without further guarantees or additional measures.

Zendesk

We use the CRM system “Zendesk” from the provider Zendesk, Inc., 989 Market Street #300, San Francisco, CA 94102, USA, in order to process user inquiries faster and more efficiently (legitimate interest pursuant to Art. 6(1)(f) GDPR).

Zendesk uses user data only for the technical processing of inquiries and does not pass it on to third parties. To use Zendesk, at least a correct email address must be provided. Pseudonymous use is possible. In the course of processing service inquiries, it may be necessary to collect further data (e.g., name, address, telephone number). The use of Zendesk is optional and serves to improve and accelerate our customer and user service.

If users do not agree to data collection via and data storage in Zendesk’s external system, we offer them alternative contact options for submitting service inquiries by email, telephone, fax, or post.

Website: https://www.zendesk.de; Privacy Policy: https://www.zendesk.de/company/customers-partners/privacy-policy/; Standard Contractual Clauses (guaranteeing the level of data protection for processing in third countries): Binding Corporate Rules as a basis for US data transfers: https://www.zendesk.de/company/privacy-and-data-protection/#data-processing-agreement.

The US company Zendesk, Inc. is also certified under the EU-US Data Privacy Framework. An adequacy decision pursuant to Art. 45 GDPR is therefore in place, meaning that a transfer of personal data may take place without further guarantees or additional measures.

10. Newsletter

10.1. General information on newsletter distribution

The following information is intended to inform you about the content of our newsletter as well as the registration, distribution, and statistical analytics procedures, and your rights of objection. By subscribing to our newsletter, you agree to receive it and consent to the procedures described.

Content of the newsletter: We send newsletters, emails, and other electronic notifications containing promotional information (hereinafter referred to as “newsletter”) only with the consent of the recipients or with legal permission. If the content of the newsletter is specifically described during registration, this content is decisive for the user’s consent. Otherwise, our newsletters contain information about our services and us.

Double opt-in and logging: Registration for our newsletter takes place via a so-called double opt-in procedure. This means that after registering, you will receive an email asking you to confirm your registration. This confirmation is necessary to prevent anyone from registering with someone else’s email address. Registrations for the newsletter are logged in order to verify the registration process in accordance with legal requirements.

This includes storing the time of registration and confirmation, as well as the IP address. Any changes to your data stored with the distribution service provider are also logged.

Registration data: To subscribe to the newsletter, it is sufficient to provide your email address. Optionally, we ask you to provide a name for the purpose of personal address in the newsletter.

The distribution of the newsletter and the performance measurement associated with it are carried out on the basis of the recipients’ consent pursuant to Art. 6 para. 1 lit. a, Art. 7 GDPR in conjunction with Sec. 7 para. 2 No. 3 UWG or on the basis of legal permission pursuant to Sec. 7 para. 3 UWG.

The registration process is logged on the basis of our legitimate interests pursuant to Art. 6 para. 1 lit. f GDPR. Our interest is directed towards the use of a user-friendly and secure newsletter system that serves both our business interests and meets user expectations, and furthermore allows us to provide proof of consent.

Cancellation/Revocation – You can cancel the receipt of our newsletter at any time, i.e., revoke your consent. A link to cancel the newsletter can be found at the end of each newsletter. We may store the unsubscribed email addresses for up to three years based on our legitimate interests before deleting them in order to be able to prove a previously given consent. The processing of this data is limited to the purpose of a potential defense against claims. An individual request for deletion is possible at any time, provided that the former existence of consent is confirmed at the same time.

10.2. Performance measurement for newsletters

The newsletters contain a so-called “web beacon”, i.e., a pixel-sized file that is retrieved from our server when the newsletter is opened, or, if we use a distribution service provider, from their server. As part of this retrieval, technical information, such as information about the browser and your system, as well as your IP address and the time of retrieval, are initially collected.

This information is used for the technical improvement of the services based on technical data or target groups and their reading behavior based on their retrieval locations (which can be determined using the IP address) or access times. Statistical surveys also include determining whether the newsletters are opened, when they are opened, and which links are clicked. Although this information can be assigned to individual newsletter recipients for technical reasons, it is neither our endeavor nor, if used, that of the distribution service provider to monitor individual users. Rather, the analytics serve us to recognize the reading habits of our users and to adapt our content to them or to send different content according to the interests of our users.

10.3. Further information on processing operations, procedures, and services

Newsletters may be distributed by the distribution service provider Mailjet SAS, 13-13 bis, rue de l’Aubrac, 75012 Paris, France. You can view the privacy policy of the distribution service provider here: https://www.mailjet.de/privacy-policy/. The distribution service provider is employed on the basis of our legitimate interests pursuant to Art. 6 para. 1 lit. f GDPR and a data processing agreement pursuant to Art. 28 para. 3 sentence 1 GDPR.

The distribution service provider may use the recipients’ data in anonymized form, i.e., without assignment to a user, to optimize or improve its own services, e.g., for the technical optimization of distribution and the presentation of the newsletters, or for statistical purposes. However, the distribution service provider does not use the data of our newsletter recipients to write to them themselves or to pass the data on to third parties.

11. Presence in social networks (Social Media)

11.1. General information on presence in social networks

We maintain online presences within social networks and process user data in this context in order to communicate with users active there or to offer information about us.

We point out that user data may be processed outside the European Union. This may result in risks for users because, for example, it could make it more difficult to enforce users’ rights.

Furthermore, user data within social networks is usually processed for market research and advertising purposes. For example, user profiles can be created based on user behavior and the resulting interests of users. The user profiles can in turn be used, for example, to place advertisements inside and outside the networks that presumably correspond to the interests of the users. For these purposes, cookies are usually stored on the users’ computers, in which the user behavior and interests of the users are stored. Furthermore, data can also be stored in the user profiles independently of the devices used by the users (especially if the users are members of the respective platforms and are logged into them).

For a detailed description of the respective forms of processing and the possibilities of objection (opt-out), we refer to the privacy policies and information provided by the operators of the respective networks.

Also in the case of requests for information and the assertion of data subject rights, we point out that these can be asserted most effectively with the providers. Only the providers have access to the user data in each case and can directly take appropriate measures and provide information. Should you nevertheless require assistance, you can contact us.

The data processed includes contact data (e.g., email, telephone numbers); content data (e.g., entries in online forms), usage data (e.g., websites visited, interest in content, access times), meta/communication data (e.g., device information, IP addresses).

Those affected are all users of the respective social networks (e.g., website visitors, users of online services). The purpose of the processing lies in contact requests and communication, feedback (e.g., collecting feedback via online forms), marketing, and the processing is based on legitimate interest (Art. 6 para. 1 sentence 1 lit. f GDPR).

11.2. Further information on processing operations, procedures, and services

Facebook Pages

With regard to profiles within the social network Facebook, we are jointly responsible with Meta Platforms Ireland Limited for the collection (but not the further processing) of data from visitors to our Facebook page (so-called “Fan Page”). This data includes information about the types of content users view or interact with, or the actions they take (see under “Things you and others do and provide” in the Facebook Data Policy: https://www.facebook.com/policy), as well as information about the devices used by users (e.g., IP addresses, operating system, browser type, language settings, cookie data; see under “Device Information” in the Facebook Data Policy: https://www.facebook.com/policy). As explained in the Facebook Data Policy under “How do we use this information?”, Facebook also collects and uses information to provide analytics services, known as “Page Insights”, to page operators to help them understand how people interact with their pages and the content associated with them. We have entered into a specific agreement with Facebook (“Information about Page Insights”, https://www.facebook.com/legal/terms/page_controller_addendum), which regulates in particular the security measures Facebook must observe and in which Facebook has agreed to fulfill data subject rights (i.e., users can, for example, direct requests for information or deletion directly to Facebook). The rights of users (in particular to information, deletion, objection, and lodging a complaint with the competent supervisory authority) are not restricted by the agreements with Facebook. Further information can be found in the “Information about Page Insights” (https://www.facebook.com/legal/terms/information_about_page_insights_data); Service provider: Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland; Website: https://www.facebook.com; Privacy Policy: https://www.facebook.com/about/privacy; Standard Contractual Clauses (guaranteeing the level of data protection for processing in third countries): https://www.facebook.com/legal/EU_data_transfer_addendum; Further information: Joint Controller Agreement: https://www.facebook.com/legal/terms/information_about_page_insights_data.

LinkedIn

Social network; Service provider: LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland; Website: https://www.linkedin.com; Privacy Policy: https://www.linkedin.com/legal/privacy-policy; Data processing agreement: https://legal.linkedin.com/dpa; Standard Contractual Clauses (guaranteeing the level of data protection for processing in third countries): https://legal.linkedin.com/dpa; Possibility of objection (Opt-Out): https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.

Vimeo

Social network and video platform; Service provider: Vimeo Inc., Attention: Legal Department, 555 West 18th Street New York, New York 10011, USA; Website: https://vimeo.com; Privacy Policy: https://vimeo.com/privacy.

Xing

Social network; Service provider: XING AG, Dammtorstraße 29-32, 20354 Hamburg, Germany; Website: https://www.xing.de; Privacy Policy: https://privacy.xing.com/de/datenschutzerklaerung.

YouTube

Social network and video platform; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, Parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; Privacy Policy: https://policies.google.com/privacy; Possibility of objection (Opt-Out): https://adssettings.google.com/authenticated.

The parent company Google LLC is certified as a US company under the EU-US Data Privacy Framework. An adequacy decision pursuant to Art. 45 GDPR is therefore in place, meaning that a transfer of personal data may take place without further guarantees or additional measures.

12. Cookies, Google Analytics, and Marketing

12.1. Cookies and right to object to direct marketing

“Cookies” refer to small files that are stored on users’ computers. Different information can be stored within the cookies. A cookie serves primarily to store information about a user (or the device on which the cookie is stored) during or after their visit to an online offer. Temporary cookies, or “session cookies” or “transient cookies”, are cookies that are deleted after a user leaves an online offer and closes their browser. In such a cookie, for example, the contents of a shopping cart in an online shop or a login status can be stored. Cookies are referred to as “permanent” or “persistent” if they remain stored even after the browser is closed. For example, the login status can be stored to simplify the login process for the user. Likewise, the interests of users can be stored in such a cookie, which are used for reach measurement or marketing purposes. “Third-party cookies” refer to cookies offered by providers other than the controller operating the online offer (otherwise, if they are only its cookies, they are called “first-party cookies”). Necessary cookies – also called essential or strictly necessary cookies – can be absolutely essential for the operation of a website, e.g., to store logins and/or other user inputs, or for security reasons. Statistical, marketing, and/or personalization cookies are used, for example, as part of reach measurement when user interests or user behavior are stored in a user profile. Such cookies serve, for example, to display content to users that corresponds to their potential interests.

We may use temporary and permanent cookies and clarify this within the framework of our privacy policy. Unless we provide information to the contrary regarding the storage period of permanent cookies, the storage period can be up to two years.

The legal basis on which we process personal data with the help of cookies depends on whether you are asked for consent. If you consent to the use of cookies, the legal basis for processing your data is the declared consent. Otherwise, the data processed with the help of cookies is processed on the basis of our legitimate interests (e.g., in the business operation of our online offer and its improvement) or to fulfill our contractual obligations.

Depending on whether the processing is based on consent or legal permission, you have the option at any time to revoke a previously granted consent or to object to the processing of your data by cookie technologies (“opt-out”). A general objection to the use of cookies used for online marketing purposes can be declared for a large number of services, especially in the case of tracking, via the US website http://www.aboutads.info/choices/ or the EU website http://www.youronlinechoices.de/. Furthermore, the storage of cookies can be achieved by disabling them in the browser settings. Please note that in this case, it may not be possible to use all functions of this online offer.

BorlabsCookie

Cookie consent management; Service provider: Borlabs; Website: https://de.borlabs.io/borlabs-cookie/; Further information: An individual user ID, language, types of consent, and the time of submission are stored on the server side and in the cookie on the user’s device.

Cloudflare Content Delivery Network

We use a so-called “Content Delivery Network” (CDN) offered by Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA. A CDN is a service that helps deliver content from our online offer, especially large media files such as graphics or scripts, more quickly using regionally distributed servers connected via the Internet. The processing of user data is carried out solely for the aforementioned purposes and to maintain the security and functionality of the CDN. Further information can be found in Cloudflare’s privacy policy: https://www.cloudflare.com/security-policy.

The US company Cloudflare, Inc. is also certified under the EU-US Data Privacy Framework. An adequacy decision pursuant to Art. 45 GDPR is therefore in place, meaning that a transfer of personal data may take place without further guarantees or additional measures.

12.2. Use of Google products and related services

12.2.1. Google Analytics

On the basis of our legitimate interests (i.e., interest in the analysis, optimization, and economic operation of our online offer within the meaning of Art. 6 para. 1 lit. f GDPR) or user consent, we use Google Analytics, a web analytics service provided by Google LLC (“Google”). Google uses cookies. The information generated by the cookie about the use of the online offer by users is generally transmitted to a Google server in the USA and stored there.

Google will use this information on our behalf to evaluate the use of our online offer by users, to compile reports on activities within this online offer, and to provide us with further services related to the use of this online offer and internet usage. In doing so, pseudonymous user profiles can be created from the processed data.

We only use Google Analytics with IP anonymization activated. This means that the IP address of users is shortened by Google within member states of the European Union or in other contracting states to the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there.

The IP address transmitted by the user’s browser will not be merged with other Google data. Users can prevent the storage of cookies by setting their browser software accordingly; users can also prevent the collection of data generated by the cookie and related to their use of the online offer by Google, as well as the processing of this data by Google, by downloading and installing the browser plugin available under the following link: http://tools.google.com/dlpage/gaoptout.

Further information on data use by Google, setting and objection options, can be found in Google’s privacy policy (https://policies.google.com/technologies/ads) and in the settings for the display of advertisements by Google (https://adssettings.google.com/authenticated).

Furthermore, the parent company Google LLC is certified as a US company under the EU-US Data Privacy Framework. An adequacy decision pursuant to Art. 45 GDPR is therefore in place, meaning that a transfer of personal data may take place without further guarantees or additional measures.

12.2.2. Target group creation with Google Analytics

We use Google Analytics to display the advertisements placed within the advertising services of Google and its partners only to those users who have also shown an interest in our online offer or who possess certain characteristics (e.g., interests in certain topics or products determined on the basis of the websites visited) that we transmit to Google (so-called “remarketing” or “Google Analytics audiences”). With the help of remarketing audiences, we also want to ensure that our advertisements correspond to the potential interest of users.

12.2.3. Google Tag Manager

Google Tag Manager is a solution with which we can manage so-called website tags via an interface (and thus, for example, integrate Google Analytics and other Google marketing services into our online offer). The Tag Manager itself (which implements the tags) does not process any personal data of users. With regard to the processing of users’ personal data, reference is made to the following information on Google services. Use Policy: https://www.google.com/intl/de/tagmanager/use-policy.html.

12.2.4. Google AdWords and Conversion Measurement

On the basis of our legitimate interests (i.e., interest in the analysis, optimization, and economic operation of our online offer within the meaning of Art. 6 para. 1 lit. f GDPR), we use the services of Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, (“Google”).

We use the online marketing procedure Google “AdWords” to place advertisements in the Google advertising network (e.g., in search results, in videos, on websites, etc.) so that they are displayed to users who have a presumed interest in the advertisements. This allows us to display advertisements for and within our online offer in a more targeted manner, in order to present users only with advertisements that potentially correspond to their interests. If, for example, a user is shown advertisements for products in which they have shown an interest on other online offers, this is referred to as “remarketing”. For these purposes, when our website and other websites on which the Google advertising network is active are accessed, a code from Google is executed directly by Google and so-called (re)marketing tags (invisible graphics or code, also referred to as “web beacons”) are integrated into the website. With their help, an individual cookie, i.e., a small file, is stored on the user’s device (comparable technologies can also be used instead of cookies). This file records which websites the user has visited, what content they are interested in, and which offers the user has clicked on, as well as technical information about the browser and operating system, referring websites, time of visit, and further information on the use of the online offer.

Furthermore, we receive an individual “conversion cookie”. The information obtained with the help of the cookie is used by Google to create conversion statistics for us. However, we only learn the anonymous total number of users who clicked on our advertisement and were redirected to a page provided with a conversion tracking tag. However, we do not receive any information that can be used to personally identify users.

User data is processed pseudonymously within the framework of the Google advertising network. This means that Google does not store and process, for example, the name or email address of users, but processes the relevant data on a cookie basis within pseudonymous user profiles. This means that from Google’s perspective, the advertisements are not managed and displayed for a specifically identified person, but for the cookie holder, regardless of who this cookie holder is. This does not apply if a user has expressly allowed Google to process the data without this pseudonymization. The information collected about users is transmitted to Google and stored on Google’s servers in the USA.

Further information on data use by Google, setting and objection options, can be found in Google’s privacy policy (https://policies.google.com/technologies/ads) and in the settings for the display of advertisements by Google (https://adssettings.google.com/authenticated).

Furthermore, the parent company Google LLC is certified as a US company under the EU-US Data Privacy Framework. An adequacy decision pursuant to Art. 45 GDPR is therefore in place, meaning that a transfer of personal data may take place without further guarantees or additional measures.

12.2.5. Google DoubleClick

On the basis of our legitimate interests (i.e., interest in the analysis, optimization, and economic operation of our online offer within the meaning of Art. 6 para. 1 lit. f GDPR), we use the services of Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, (“Google”).

We use the online marketing procedure Google “DoubleClick” to place advertisements in the Google advertising network (e.g., in search results, in videos, on websites, etc.). DoubleClick is characterized by the fact that advertisements are displayed in real time based on the presumed interests of users. This allows us to display advertisements for and within our online offer in a more targeted manner, in order to present users only with advertisements that potentially correspond to their interests. If, for example, a user is shown advertisements for products in which they have shown an interest on other online offers, this is referred to as “remarketing”. For these purposes, when our website and other websites on which the Google advertising network is active are accessed, a code from Google is executed directly by Google and so-called (re)marketing tags (invisible graphics or code, also referred to as “web beacons”) are integrated into the website. With their help, an individual cookie, i.e., a small file, is stored on the user’s device (comparable technologies can also be used instead of cookies). This file records which websites the user has visited, what content they are interested in, and which offers the user has clicked on, as well as technical information about the browser and operating system, referring websites, time of visit, and further information on the use of the online offer.

The IP address of users is also recorded, whereby it is shortened within member states of the European Union or in other contracting states to the Agreement on the European Economic Area and is only transmitted in full to a Google server in the USA and shortened there in exceptional cases. The aforementioned information can also be combined by Google with such information from other sources. If the user subsequently visits other websites, advertisements tailored to them can be displayed based on their presumed interests on the basis of their user profile.

User data is processed pseudonymously within the framework of the Google advertising network. This means that Google does not store and process, for example, the name or email address of users, but processes the relevant data on a cookie basis within pseudonymous user profiles. This means that from Google’s perspective, the advertisements are not managed and displayed for a specifically identified person, but for the cookie holder, regardless of who this cookie holder is. This does not apply if a user has expressly allowed Google to process the data without this pseudonymization. The information collected about users by Google marketing services is transmitted to Google and stored on Google’s servers in the USA.

Further information on data use by Google, setting and objection options, can be found in Google’s privacy policy (https://policies.google.com/technologies/ads) and in the settings for the display of advertisements by Google (https://adssettings.google.com/authenticated).

Furthermore, the parent company Google LLC is certified as a US company under the EU-US Data Privacy Framework. An adequacy decision pursuant to Art. 45 GDPR is therefore in place, meaning that a transfer of personal data may take place without further guarantees or additional measures.

12.2.6. Leadfeeder

Based on our legitimate interests in data processing pursuant to Art. 6 para. 1 lit. f GDPR, we use the Leadfeeder service to acquire prospects (leads). Leadfeeder uses the IP addresses of visitors to our website provided via Google Analytics and links these IP addresses with information about the companies that can be found on the Internet under these IP addresses. Due to the shortening of the IP addresses of visitors to our website, which is carried out by default when using Google Analytics, a direct personal reference is not established; only companies can be inferred as a presumption via Leadfeeder. Leadfeeder is integrated into our CRM system. Leadfeeder is a service provided by Liidio Oy, Mikonkatu 17 C, Helsinki 00100, Finland. Website: https://www.leadfeeder.com; Privacy Policy: https://www.leadfeeder.com/privacy; further information on Leadfeeder and compatibility with the General Data Protection Regulation: https://www.leadfeeder.com/leadfeeder-and-gdpr/. You can prevent the processing of data about your use of our site by Leadfeeder by means of an opt-out. More information on this can be found at: https://yourdata.leadfeeder.com/.