Data Privacy Policy
Privacy Policy
1. Data Protection at a Glance
General information
The following information provides a simple overview of what happens to your personal data when you visit this website. Personal data means any data that can be used to identify you personally. Detailed information on data protection can be found in the Privacy Policy set out below.
Who is responsible for data collection on this website?
The data processing on this website is carried out by the website operator. The operator’s contact details can be found in the section “Information on the Controller” in this Privacy Policy.
How do we collect your data?
Some data is collected when you provide it to us. This may, for example, be data that you enter into a contact form.
Other data is collected automatically or after you have given your consent when you visit the website by our IT systems. This primarily includes technical data, such as your internet browser, operating system or the time at which the website was accessed. This data is collected automatically as soon as you access this website.
What do we use your data for?
Some of the data is collected to ensure the proper functioning of the website. Other data may be used to analyse your user behaviour. If contracts can be concluded or initiated via the website, the data transmitted will also be processed for contractual offers, orders or other enquiries relating to contracts.
What rights do you have regarding your data?
You have the right at any time to obtain information free of charge about the origin, recipients and purpose of your stored personal data. You also have the right to request the rectification or deletion of this data. If you have given your consent to data processing, you may withdraw this consent at any time with effect for the future. Furthermore, under certain circumstances, you have the right to request the restriction of the processing of your personal data. You also have the right to lodge a complaint with the competent supervisory authority.
You can contact us at any time regarding this or any other questions concerning data protection.
Analytics Tools and Third-Party Tools
When you visit this website, your browsing behaviour may be statistically analysed. This is mainly carried out using analytics programs.
Detailed information about these analytics programs can be found in the following Privacy Policy.Data Collection on this Website
Who is the responsible party for the recording of data on this website (i.e., the “controller”)?
The data on this website is processed by the operator of the website, whose contact information is available under section “Information about the responsible party (referred to as the “controller” in the GDPR)” in this Privacy Policy.
2. Hosting and Content Delivery Networks (CDN)
We host the content of our website with the following provider:
Amazon Web Services (AWS)
The provider is Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, 1855 Luxembourg (hereinafter referred to as “AWS”).
When you visit our website, your personal data is processed on AWS servers. Personal data may also be transferred to AWS’s parent company in the United States. Data transfers to the United States are based on the EU Standard Contractual Clauses. Details can be found here:
https://aws.amazon.com/de/blogs/security/aws-gdpr-data-processing-addendum/
Further information can be found in the AWS Privacy Notice:
https://aws.amazon.com/de/privacy/?nc1=f_pr
The use of AWS is based on Art. 6(1)(f) GDPR. We have a legitimate interest in ensuring the most reliable possible presentation of our website. Where consent has been requested, processing is carried out exclusively on the basis of Art. 6(1)(a) GDPR and Section 25(1) TDDDG, insofar as the consent covers the storage of cookies or access to information on the user’s terminal device, e.g. device fingerprinting, within the meaning of the TDDDG. Consent may be withdrawn at any time.
The company is certified under the EU-US Data Privacy Framework (“DPF”). The DPF is an agreement between the European Union and the United States intended to ensure compliance with European data protection standards for data processing in the United States. Every company certified under the DPF undertakes to comply with these data protection standards. Further information can be obtained from the provider at:
https://www.dataprivacyframework.gov/participant/5776
Data Processing Agreement
We have concluded a data processing agreement (“DPA”) for the use of the service referred to above. This is a contract required under data protection law that ensures that the provider processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.
Amazon CloudFront CDN
We use the Amazon CloudFront content delivery network. The provider is Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxembourg (hereinafter referred to as “Amazon”).
Amazon CloudFront CDN is a globally distributed content delivery network. The transfer of information between your browser and our website is technically routed through the content delivery network. This enables us to improve the global availability and performance of our website.
The use of Amazon CloudFront CDN is based on our legitimate interest in providing our website as reliably and securely as possible (Art. 6(1)(f) GDPR).
Data transfers to the United States are based on the Standard Contractual Clauses of the European Commission. Details can be found here:
https://aws.amazon.com/de/blogs/security/aws-gdpr-data-processing-addendum/
Further information about Amazon CloudFront CDN can be found here:
https://d1.awsstatic.com/legal/privacypolicy/AWS_Privacy_Notice__German_Translation.pdf
The company is certified under the EU-US Data Privacy Framework (“DPF”). The DPF is an agreement between the European Union and the United States intended to ensure compliance with European data protection standards for data processing in the United States. Every company certified under the DPF undertakes to comply with these data protection standards. Further information can be obtained from the provider at:
https://www.dataprivacyframework.gov/participant/5776
Data Processing Agreement
We have concluded a data processing agreement (“DPA”) for the use of the service referred to above. This is a contract required under data protection law that ensures that the provider processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.
Storyblok
We use the Storyblok content management system to manage and provide the content of our website. The provider is Storyblok GmbH, Peter-Behrens-Platz 2, 4020 Linz, Austria (hereinafter referred to as “Storyblok”).
Storyblok is a cloud-based headless content management system that enables us to create, manage and provide content on our website. When content provided via Storyblok is accessed, technically necessary data may be processed. This may include, in particular, the IP address, date and time of access, information about the browser and operating system used, as well as the content or files accessed.
The use of Storyblok is based on Art. 6(1)(f) GDPR. We have a legitimate interest in the technically reliable, secure and efficient management and provision of our website and its content.
Storyblok uses subprocessors to provide its services. These include, in particular, Amazon Web Services EMEA SARL (“AWS”). Depending on the services used and the configuration, personal data may also be processed outside the European Union or the European Economic Area. Where data is transferred to countries outside the EU or EEA, such transfer takes place in accordance with the requirements of Art. 44 et seq. GDPR, in particular on the basis of an adequacy decision by the European Commission or appropriate safeguards such as the European Commission’s Standard Contractual Clauses.
Further information about data protection at Storyblok can be found at:
https://www.storyblok.com/legal/privacy-policy
Data Processing Agreement
We have concluded a data processing agreement with Storyblok pursuant to Art. 28 GDPR. This ensures that Storyblok processes personal data solely in accordance with our instructions and in compliance with the applicable data protection requirements.
3. General Information and Mandatory Information
Data Protection
The operators of this website take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with statutory data protection regulations and this Privacy Policy.
When you use this website, various types of personal data are collected. Personal data is data that can be used to identify you personally. This Privacy Policy explains what data we collect and what we use it for. It also explains how and for what purpose this is done.
Please note that data transmission over the internet, e.g. when communicating by email, may be subject to security vulnerabilities. Complete protection of data against access by third parties is not possible.
Information on the Controller
The controller responsible for data processing on this website is:
bio-tec Biologische Naturverpackungen GmbH & Co. KG
Werner-Heisenberg-Str. 32
46446 Emmerich am Rhein
Germany
Telephone: +49 (0) 2822 92510
Email: info@biotec.de
The controller is the natural or legal person who, alone or jointly with others, determines the purposes and means of processing personal data, e.g. names, email addresses or similar information.
Storage Period
Unless a more specific storage period is stated in this Privacy Policy, your personal data will remain with us until the purpose for the data processing no longer applies. If you submit a legitimate request for deletion or withdraw your consent to data processing, your data will be deleted unless we have other legally permissible reasons for storing your personal data, e.g. retention periods under tax or commercial law. In the latter case, the data will be deleted once these reasons cease to apply.
General Information on the Legal Bases for Data Processing on this Website
Where you have consented to data processing, we process your personal data on the basis of Art. 6(1)(a) GDPR or Art. 9(2)(a) GDPR where special categories of personal data within the meaning of Art. 9(1) GDPR are processed.
In the case of explicit consent to the transfer of personal data to third countries, data processing is also carried out on the basis of Art. 49(1)(a) GDPR.
Where you have consented to the storage of cookies or access to information on your terminal device, e.g. by means of device fingerprinting, data processing is additionally carried out on the basis of Section 25(1) TDDDG. Consent may be withdrawn at any time.
Where your data is required for the performance of a contract or for taking steps prior to entering into a contract, we process your data on the basis of Art. 6(1)(b) GDPR.
Furthermore, we process your data where this is necessary to comply with a legal obligation on the basis of Art. 6(1)(c) GDPR.
Data processing may also be based on our legitimate interests pursuant to Art. 6(1)(f) GDPR.
Information on the legal basis applicable in each individual case is provided in the following sections of this Privacy Policy.
Data Protection Officer
We have appointed a Data Protection Officer.
BITsic GmbH
Mr Paul Köhler
Vesperther Trift 7
33181 Bad Wünnenberg
Germany
Telephone: +49 2953 39699-20
Email: datenschutz@bitsic.de
Recipients of Personal Data
In the course of our business activities, we work with various external parties. In some cases, this also requires personal data to be transferred to these external parties.
We only disclose personal data to external parties where this is necessary for the performance of a contract, where we are legally obliged to do so, e.g. disclosure of data to tax authorities, where we have a legitimate interest pursuant to Art. 6(1)(f) GDPR in the disclosure, or where another legal basis permits the disclosure.
When using processors, we only disclose personal data of our customers on the basis of a valid data processing agreement.
In the case of joint processing, an agreement on joint processing is concluded.
Withdrawal of Your Consent to Data Processing
Many data processing operations are only possible with your explicit consent. You may withdraw consent that you have already given at any time. The lawfulness of data processing carried out prior to the withdrawal remains unaffected by the withdrawal.
Right to Object to Data Collection in Specific Cases and to Direct Marketing (Art. 21 GDPR)
WHERE DATA PROCESSING IS CARRIED OUT ON THE BASIS OF ART. 6(1)(E) OR (F) GDPR, YOU HAVE THE RIGHT AT ANY TIME, ON GROUNDS RELATING TO YOUR PARTICULAR SITUATION, TO OBJECT TO THE PROCESSING OF YOUR PERSONAL DATA; THIS ALSO APPLIES TO PROFILING BASED ON THESE PROVISIONS.
THE LEGAL BASIS ON WHICH PROCESSING IS BASED CAN BE FOUND IN THIS PRIVACY POLICY.
IF YOU OBJECT, WE WILL NO LONGER PROCESS YOUR PERSONAL DATA CONCERNED UNLESS WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING THAT OVERRIDE YOUR INTERESTS, RIGHTS AND FREEDOMS, OR THE PROCESSING SERVES THE ESTABLISHMENT, EXERCISE OR DEFENCE OF LEGAL CLAIMS (OBJECTION PURSUANT TO ART. 21(1) GDPR).
WHERE YOUR PERSONAL DATA IS PROCESSED FOR DIRECT MARKETING PURPOSES, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF PERSONAL DATA CONCERNING YOU FOR SUCH MARKETING; THIS ALSO APPLIES TO PROFILING TO THE EXTENT THAT IT IS RELATED TO SUCH DIRECT MARKETING.
IF YOU OBJECT, YOUR PERSONAL DATA WILL SUBSEQUENTLY NO LONGER BE USED FOR DIRECT MARKETING PURPOSES (OBJECTION PURSUANT TO ART. 21(2) GDPR).
Right to Lodge a Complaint with the Competent Supervisory Authority
In the event of infringements of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, their place of work or the place of the alleged infringement.
The right to lodge a complaint is without prejudice to any other administrative or judicial remedies.
Right to Data Portability
You have the right to receive data that we process automatically on the basis of your consent or in performance of a contract in a commonly used, machine-readable format, or to have such data transmitted to a third party.
Where you request the direct transfer of the data to another controller, this will only be done where technically feasible.
Access, Rectification and Erasure
Within the framework of the applicable statutory provisions, you have the right at any time to obtain information free of charge about your stored personal data, its origin and recipients and the purpose of the data processing, and, where applicable, a right to rectification or erasure of this data.
You can contact us at any time regarding this or any other questions concerning personal data.
Right to Restriction of Processing
You have the right to request restriction of the processing of your personal data. You can contact us at any time for this purpose.
The right to restriction of processing exists in the following cases:
If you dispute the accuracy of your personal data stored by us, we generally require time to verify this. For the duration of the verification, you have the right to request restriction of the processing of your personal data.
If the processing of your personal data was or is unlawful, you may request restriction of data processing instead of erasure.
If we no longer require your personal data but you need it for the exercise, defence or establishment of legal claims, you have the right to request restriction of data processing instead of erasure.
If you have objected pursuant to Art. 21(1) GDPR, a balance must be struck between your interests and ours. For as long as it has not yet been determined whose interests prevail, you have the right to request restriction of the processing of your personal data.
Where you have restricted the processing of your personal data, such data may – apart from storage – only be processed with your consent, for the establishment, exercise or defence of legal claims, for the protection of the rights of another natural or legal person, or for reasons of important public interest of the European Union or a Member State.
SSL or TLS Encryption
For security reasons and to protect the transmission of confidential content, such as orders or enquiries that you send to us as the website operator, this website uses SSL or TLS encryption.
You can recognise an encrypted connection by the fact that the browser address bar changes from “http://” to “https://” and by the lock symbol in your browser bar.
When SSL or TLS encryption is enabled, the data you transmit to us cannot be read by third parties.
Objection to Advertising Emails
We hereby object to the use of contact details published as part of our legal notice obligations for the purpose of sending unsolicited advertising and information materials.
The website operators expressly reserve the right to take legal action in the event of unsolicited advertising information being sent, for example by means of spam emails.
4. Data Collection on this Website
Cookies
Our websites use so-called “cookies”. Cookies are small data packets and do not cause any damage to your terminal device. They are stored on your terminal device either temporarily for the duration of a session (“session cookies”) or permanently (“persistent cookies”).
Session cookies are automatically deleted at the end of your visit. Persistent cookies remain stored on your terminal device until you delete them yourself or they are automatically deleted by your web browser.
Cookies may originate from us (“first-party cookies”) or from third-party companies (“third-party cookies”). Third-party cookies enable certain services provided by third-party companies to be integrated into websites, e.g. cookies used for payment processing services.
Cookies have various functions. Many cookies are technically necessary because certain website functions would not work without them, e.g. shopping basket functionality or the display of videos. Other cookies may be used to analyse user behaviour or for advertising purposes.
Cookies that are necessary to carry out electronic communications, to provide certain functions requested by you, e.g. shopping basket functionality, or to optimise the website, e.g. cookies used to measure website audiences, are stored on the basis of Art. 6(1)(f) GDPR unless another legal basis is specified. The website operator has a legitimate interest in storing necessary cookies to ensure the technically error-free and optimised provision of its services.
Where consent to the storage of cookies and comparable recognition technologies has been requested, processing is carried out exclusively on the basis of this consent (Art. 6(1)(a) GDPR and Section 25(1) TDDDG). Consent may be withdrawn at any time.
You can configure your browser to inform you when cookies are set and to allow cookies only in individual cases, to exclude the acceptance of cookies in certain cases or generally, and to activate automatic deletion of cookies when closing your browser.
If cookies are disabled, the functionality of this website may be restricted.
Where additional cookies and services are used on this website, information about these can be found in this Privacy Policy.
Consent Management with OneTrust
Our website uses the Consent Management Platform (“CMP”) provided by OneTrust to obtain, manage and document your consent to the storage of certain cookies on your terminal device or to the use of certain technologies in compliance with data protection requirements.
The provider is OneTrust LLC, 505 North Angier Avenue, Atlanta, Georgia 30308, USA (hereinafter referred to as “OneTrust”).
When you access our website, OneTrust records and stores your consent decisions and other declarations concerning the use of cookies and comparable technologies.
For this purpose, OneTrust uses technically necessary cookies. These include, in particular, the cookies “OptanonConsent” and “OptanonAlertBoxClosed”. These are used to store your consent decision or your interaction with the consent banner and to take this into account during subsequent page visits.
In particular, the following information may be processed:
your consent and refusal decisions,
the selected cookie or service categories,
the date and time of the decision,
a technically generated consent ID, where this function is enabled,
information about your interaction with the consent banner, and
technical information required to provide the consent management function.
The processing is carried out for the purpose of obtaining, managing and documenting your data protection consents and for demonstrating the consents granted or refused.
OneTrust is used to obtain and document the legally required consent for the use of cookies and comparable technologies. The legal basis for this is Art. 6(1)(c) GDPR in conjunction with Art. 7(1) GDPR.
Where information is stored on or accessed from your terminal device solely for the purpose of providing the technically necessary consent management function, this is carried out on the basis of Section 25(2) no. 2 TDDDG.
The technically necessary cookies used store your consent decision for the configured period. Details of the cookies used, their purposes and storage periods can be viewed at any time via the cookie settings on our website. You can also change or withdraw your previous settings at any time there.
OneTrust LLC is based in the United States. The company participates in the EU-US Data Privacy Framework. Accordingly, an adequacy decision by the European Commission applies to transfers of personal data to appropriately certified companies in the United States.
Where a data transfer cannot be based on this adequacy decision, appropriate safeguards are used, in particular the European Commission’s Standard Contractual Clauses.
Further information about data protection at OneTrust can be found at:
https://www.onetrust.com/privacy/
Data Processing Agreement
We have concluded a data processing agreement with OneTrust pursuant to Art. 28 GDPR. This ensures that OneTrust processes personal data solely in accordance with our instructions and in compliance with the applicable data protection requirements.
Server Log Files
The provider of the website automatically collects and stores information in so-called server log files, which your browser automatically transmits to us.
These are:
browser type and browser version,
operating system used,
referrer URL,
host name of the accessing computer,
time of the server request,
IP address.
This data is not combined with other data sources.
The collection of this data is based on Art. 6(1)(f) GDPR. The website operator has a legitimate interest in the technically error-free presentation and optimisation of the website – for this purpose, server log files must be collected.
Contact Form
If you submit enquiries to us via the contact form, the information you provide in the enquiry form, including the contact details you provide there, will be stored by us for the purpose of processing the enquiry and in case of follow-up questions. We will not disclose this data without your consent.
The processing of this data is based on Art. 6(1)(b) GDPR where your enquiry relates to the performance of a contract or is necessary in order to take steps prior to entering into a contract.
In all other cases, processing is based on our legitimate interest in effectively handling enquiries addressed to us (Art. 6(1)(f) GDPR) or on your consent (Art. 6(1)(a) GDPR) where such consent has been requested. Consent may be withdrawn at any time.
The data you enter in the contact form will remain with us until you request deletion, withdraw your consent to storage or the purpose for storing the data no longer applies, e.g. after your enquiry has been fully processed.
Mandatory statutory provisions, in particular retention periods, remain unaffected.
Enquiries by Email, Telephone or Fax
If you contact us by email, telephone or fax, your enquiry, including all personal data resulting from it, such as your name and the content of your enquiry, will be stored and processed by us for the purpose of handling your request. We will not disclose this data without your consent.
The processing of this data is based on Art. 6(1)(b) GDPR where your enquiry relates to the performance of a contract or is necessary in order to take steps prior to entering into a contract.
In all other cases, processing is based on our legitimate interest in effectively handling enquiries addressed to us (Art. 6(1)(f) GDPR) or on your consent (Art. 6(1)(a) GDPR) where such consent has been requested. Consent may be withdrawn at any time.
The data transmitted to us in connection with your enquiry will remain with us until you request deletion, withdraw your consent to storage or the purpose for storing the data no longer applies, e.g. after your enquiry has been fully processed.
Mandatory statutory provisions, in particular statutory retention periods, remain unaffected.
5. Analytics Tools and Advertising
Google Tag Manager
We use Google Tag Manager. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Google Tag Manager is a tool that enables us to integrate tracking or statistics tools and other technologies into our website. Google Tag Manager itself does not create user profiles, store cookies or perform any independent analyses. It merely serves to manage and deploy the tools integrated through it.
However, Google Tag Manager collects your IP address, which may also be transferred to Google’s parent company in the United States.
The use of Google Tag Manager is based on Art. 6(1)(f) GDPR. The website operator has a legitimate interest in the quick and straightforward integration and management of various tools on the website.
Where consent has been requested, processing is carried out exclusively on the basis of Art. 6(1)(a) GDPR and Section 25(1) TDDDG, insofar as the consent covers the storage of cookies or access to information on the user’s terminal device, e.g. device fingerprinting, within the meaning of the TDDDG. Consent may be withdrawn at any time.
The company is certified under the EU-US Data Privacy Framework (“DPF”). The DPF is an agreement between the European Union and the United States intended to ensure compliance with European data protection standards for data processing in the United States. Every company certified under the DPF undertakes to comply with these data protection standards.
Further information can be obtained from the provider at:
https://www.dataprivacyframework.gov/participant/5780
Google Analytics
This website uses functions of the Google Analytics web analytics service. The provider is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.
Google Analytics enables the website operator to analyse the behaviour of website visitors. In doing so, the website operator receives various usage data, such as page views, length of visit, operating systems used and the user’s origin. This data is assigned to the respective user device. It is not assigned to a user ID.
Furthermore, Google Analytics may allow us to record, among other things, your mouse and scroll movements and clicks. Google Analytics also uses various modelling approaches to supplement the collected datasets and uses machine-learning technologies for data analysis.
Google Analytics uses technologies that enable users to be recognised for the purpose of analysing user behaviour, e.g. cookies or device fingerprinting. The information collected by Google about the use of this website is generally transferred to a Google server in the United States and stored there.
The use of this service is based on your consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) TDDDG. Consent may be withdrawn at any time.
Data transfers to the United States are based on the European Commission’s Standard Contractual Clauses. Details can be found here:
https://business.safety.google/adscontrollerterms/sccs/
The company is certified under the EU-US Data Privacy Framework (“DPF”). The DPF is an agreement between the European Union and the United States intended to ensure compliance with European data protection standards for data processing in the United States. Every company certified under the DPF undertakes to comply with these data protection standards.
Further information can be obtained from the provider at:
https://www.dataprivacyframework.gov/participant/5780
IP Anonymisation
Google Analytics IP anonymisation is activated. This means that your IP address is truncated by Google within Member States of the European Union or other states party to the Agreement on the European Economic Area before being transferred to the United States.
Only in exceptional cases will the full IP address be transferred to a Google server in the United States and truncated there.
On behalf of the operator of this website, Google will use this information to evaluate your use of the website, compile reports on website activities and provide other services relating to website and internet usage to the website operator.
The IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data.
Browser Plugin
You can prevent the collection and processing of your data by Google by downloading and installing the browser plugin available at:
https://tools.google.com/dlpage/gaoptout?hl=en
Further information about how Google Analytics handles user data can be found in Google’s privacy information:
https://support.google.com/analytics/answer/6004245?hl=en
Data Processing Agreement
We have concluded a data processing agreement with Google and fully implement the strict requirements of the German data protection authorities when using Google Analytics.
6. Plugins and Tools
Google reCAPTCHA
We use “Google reCAPTCHA” (hereinafter referred to as “reCAPTCHA”) on this website. The provider is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.
The purpose of reCAPTCHA is to determine whether data entered on this website, e.g. in a contact form, is being entered by a human or by an automated program.
For this purpose, reCAPTCHA analyses the behaviour of the website visitor based on various characteristics. This analysis begins automatically as soon as the website visitor enters the website.
For the analysis, reCAPTCHA evaluates various information, e.g. IP address, the amount of time the website visitor spends on the website or mouse movements made by the user. The data collected during the analysis is forwarded to Google.
The reCAPTCHA analyses run entirely in the background. Website visitors are not informed that an analysis is taking place.
In this context, Google acts solely as a processor within the meaning of Art. 28 GDPR and will not use the data collected in this way for its own purposes. The tool is used on the basis of a data processing agreement (“DPA”) with Google.
The storage and analysis of the data is based on Art. 6(1)(f) GDPR. The website operator has a legitimate interest in protecting its web services against abusive automated access and spam.
Where consent has been requested, processing is carried out exclusively on the basis of Art. 6(1)(a) GDPR and Section 25(1) TDDDG, insofar as the consent covers the storage of cookies or access to information on the user’s terminal device, e.g. device fingerprinting, within the meaning of the TDDDG. Consent may be withdrawn at any time.
The company is certified under the EU-US Data Privacy Framework (“DPF”). The DPF is an agreement between the European Union and the United States intended to ensure compliance with European data protection standards for data processing in the United States. Every company certified under the DPF undertakes to comply with these data protection standards.
Further information can be obtained from the provider at:
https://www.dataprivacyframework.gov/participant/5780
7. Audio and Video Conferencing
Data Processing
For communication with our customers, we use, among other things, online conferencing tools. The specific tools we use are listed below.
If you communicate with us by video or audio conference via the internet, your personal data will be collected and processed by us and by the provider of the respective conferencing tool.
The conferencing tools collect all data that you provide or use in order to use the tools, such as your email address and/or telephone number.
The conferencing tools also process the duration of the conference, the start and end time of participation in the conference, the number of participants and other “context information” relating to the communication process (“metadata”).
Furthermore, the provider of the tool processes all technical data required to handle the online communication. This includes, in particular, IP addresses, MAC addresses, device IDs, device type, operating system type and version, client version, camera type, microphone or speakers and the type of connection.
Where content is exchanged, uploaded or otherwise provided within the tool, this content is also stored on the servers of the tool providers.
Such content includes, in particular, cloud recordings, chat or instant messages, voicemails, uploaded photos and videos, files, whiteboards and other information shared while using the service.
Please note that we do not have full control over the data processing operations of the tools used. Our options are largely determined by the corporate policies of the respective provider.
Further information about data processing by the conferencing tools can be found in the privacy policies of the respective tools listed below.
Purpose and Legal Bases
The conferencing tools are used to communicate with prospective or existing contractual partners or to provide certain services to our customers (Art. 6(1)(b) GDPR).
In addition, the use of these tools serves to generally simplify and accelerate communication with us or our company, based on our legitimate interest within the meaning of Art. 6(1)(f) GDPR.
Where consent has been requested, the respective tools are used on the basis of this consent. Consent may be withdrawn at any time with effect for the future.
Storage Period
The data collected directly by us via the video and conferencing tools will be deleted from our systems as soon as you request deletion, withdraw your consent to storage or the purpose for the data storage no longer applies.
Stored cookies remain on your terminal device until you delete them.
Mandatory statutory retention periods remain unaffected.
We have no control over the storage period of your data that is stored by the operators of the conferencing tools for their own purposes. For details, please contact the operators of the conferencing tools directly.
Conferencing Tools Used
We use the following conferencing tools:
Microsoft Teams
We use Microsoft Teams. The provider is Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland.
Details on data processing can be found in Microsoft’s Privacy Statement:
https://privacy.microsoft.com/en-gb/privacystatement
The company is certified under the EU-US Data Privacy Framework (“DPF”). The DPF is an agreement between the European Union and the United States intended to ensure compliance with European data protection standards for data processing in the United States. Every company certified under the DPF undertakes to comply with these data protection standards.
Further information can be obtained from the provider at:
https://www.dataprivacyframework.gov/participant/6474
Data Processing Agreement
We have concluded a data processing agreement (“DPA”) for the use of the service referred to above. This is a contract required under data protection law that ensures that the provider processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.
8. Our Own Services
Handling of Applicant Data
We offer you the opportunity to apply for a position with us, e.g. by email, by post or via an online application form. In the following, we provide information about the scope, purpose and use of your personal data collected as part of the application process.
We assure you that your data will be collected, processed and used in accordance with applicable data protection law and all other statutory provisions and that your data will be treated as strictly confidential.
Scope and Purpose of Data Collection
If you submit an application to us, we process the personal data associated with it, e.g. contact and communication data, application documents, notes taken during interviews, etc., insofar as this is necessary for deciding whether to establish an employment relationship.
The legal basis for this is Section 26 BDSG under German law (initiation of an employment relationship), Art. 6(1)(b) GDPR (general pre-contractual measures) and – where you have given consent – Art. 6(1)(a) GDPR. Consent may be withdrawn at any time.
Within our company, your personal data will only be disclosed to persons involved in processing your application.
If your application is successful, the data submitted by you will be stored in our data processing systems on the basis of Section 26 BDSG and Art. 6(1)(b) GDPR for the purpose of carrying out the employment relationship.
As part of the application process, we may also conduct internet research relating to you. This primarily includes Google searches, LinkedIn and Xing.
The legal basis for this type of processing is our legitimate interest pursuant to Art. 6(1)(f) GDPR in obtaining an overall impression of publicly available information about you.
Data Retention Period
If we are unable to offer you a position, you reject a job offer or withdraw your application, we reserve the right to retain the data submitted by you on the basis of our legitimate interests (Art. 6(1)(f) GDPR) for up to six months after completion of the application process, i.e. rejection or withdrawal of the application.
The data will then be deleted and physical application documents destroyed.
The retention serves in particular as evidence in the event of a legal dispute.
Where it is apparent that the data will still be required after the six-month period has expired, e.g. due to an impending or pending legal dispute, deletion will only take place once the purpose of the extended retention no longer applies.
A longer retention period may also apply where you have given corresponding consent (Art. 6(1)(a) GDPR) or where statutory retention obligations prevent deletion.
Our social media appearances
This privacy policy applies to the following social media presence
Data processing through social networks
We maintain publicly available profiles in social networks. The individual social networks we use can be found below.
Social networks such as Facebook, X etc. can generally analyze your user behavior comprehensively if you visit their website or a website with integrated social media content (e.g., like buttons or banner ads). When you visit our social media pages, numerous data protection-relevant processing operations are triggered. In detail:
If you are logged in to your social media account and visit our social media page, the operator of the social media portal can assign this visit to your user account. Under certain circumstances, your personal data may also be recorded if you are not logged in or do not have an account with the respective social media portal. In this case, this data is collected, for example, via cookies stored on your device or by recording your IP address.
Using the data collected in this way, the operators of the social media portals can create user profiles in which their preferences and interests are stored. This way you can see interest-based advertising inside and outside of your social media presence. If you have an account with the social network, interest-based advertising can be displayed on any device you are logged in to or have logged in to.
Please also note that we cannot retrace all processing operations on the social media portals. Depending on the provider, additional processing operations may therefore be carried out by the operators of the social media portals. Details can be found in the terms of use and privacy policy of the respective social media portals.
Legal basis
Our social media appearances should ensure the widest possible presence on the Internet. This is a legitimate interest within the meaning of Art. 6 (1) lit. f GDPR. The analysis processes initiated by the social networks may be based on divergent legal bases to be specified by the operators of the social networks (e.g., consent within the meaning of Art. 6 (1) (a) GDPR).
Responsibility and assertion of rights
If you visit one of our social media sites (e.g., Facebook), we, together with the operator of the social media platform, are responsible for the data processing operations triggered during this visit. You can in principle protect your rights (information, correction, deletion, limitation of processing, data portability and complaint) vis-à-vis us as well as vis-à-vis the operator of the respective social media portal (e.g., Facebook).
Please note that despite the shared responsibility with the social media portal operators, we do not have full influence on the data processing operations of the social media portals. Our options are determined by the company policy of the respective provider.
Storage time
The data collected directly from us via the social media presence will be deleted from our systems as soon as you ask us to delete it, you revoke your consent to the storage or the purpose for the data storage lapses. Stored cookies remain on your device until you delete them. Mandatory statutory provisions - in particular, retention periods - remain unaffected.
We have no control over the storage duration of your data that are stored by the social network operators for their own purposes. For details, please contact the social network operators directly (e.g., in their privacy policy, see below).
Your rights
You have the right to receive information about the origin, recipient and purpose of your stored personal data at any time and free of charge. You also have the right to object, the right to data portability and the right to file a complaint with the responsible regulatory agency. Furthermore, you can request the correction, blocking, deletion and, under certain circumstances, the restriction of the processing of your personal data.
Individual social networks
We have a LinkedIn profile. The provider is the LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland. LinkedIn uses advertising cookies.
If you want to disable LinkedIn advertising cookies, please use the following link: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.
Data transmission to the US is based on the Standard Contractual Clauses (SCC) of the European Commission. Details can be found here: https://www.linkedin.com/legal/l/dpa and https://www.linkedin.com/legal/l/eu-sccs.
For details on how they handle your personal information, please refer to LinkedIn's privacy policy: https://www.linkedin.com/legal/privacy-policy.
The company is certified in accordance with the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the US, which is intended to ensure compliance with European data protection standards for data processing in the US. Every company certified under the DPF is obliged to comply with these data protection standards. For more information, please contact the provider under the following link: https://www.dataprivacyframework.gov/participant/5448