Data protection information

For the ipoox corporate group (hereinafter “ipoox” or “we”), the compliant handling and security of the processing of your personal data in accordance with data protection regulations is an important concern. With this privacy information, we would like to inform you about how we handle personal data in general and in particular.

1. Responsibilities

1.1 Controller within the meaning of data protection law

The controller within the meaning of data protection law is the natural or legal person who – alone or jointly with others – determines the purposes and means of the processing of personal data.

The controllers within the meaning of data protection law are:
ipoox presorting gmbh
Alfred-Nobel-Straße 13
D-97080 Würzburg
Phone: +49 (0) 931 730 400 0
E-Mail: info@ipoox.de
Website: www.ipoox.de

1.2 Our data protection officer

We have appointed an external Data Protection Officer for our organization. They can be reached at the following contact details:
Boris Nicolaj Willm
Resilien[i]T GmbH
Phone: +49 211 695289 92
E-Mail: dsb.ipoox-group@resilienit.de

1.3 Supervisory authority

The supervisory authority responsible for us can be contacted at:

Bavarian State Office for Data Protection Supervision (BayLDA
)
Promenade 18
91522 Ansbach
Phone: +49 (0) 981 180093-0
E-Mail: poststelle@lda.bayern.de

2. General information on data protection

2.1 What data do we process from you?

Depending on the specific processing situation and necessity, we collect and process different types of personal data. Detailed information on this is provided in this and/or separate privacy notices or, where applicable, during the data collection process to the individuals concerned.

2.2 For what purposes do we process your data and on what legal basis?

We collect and process various personal data depending on the specific processing situation. Processing is always carried out in accordance with the provisions of the General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG), or other applicable legal requirements. The relevant legal bases for us arise from Article 6(1) GDPR as follows:

2.2.1 Based on your consent
Where you have given us consent for a specific processing of your personal data, we will process your personal data on this basis. Such consent may, for example, relate to the sharing of data with partner companies, the analysis of your data for targeted advertising measures, or the sending of newsletters.

Consent is always voluntary. Refusal to give consent or withdrawal of consent will not have any negative consequences for you.

2.2.2 For the performance of contractual obligations
We process your personal data to fulfill contractual or pre-contractual obligations, or to establish a contract, for example for customer support or to respond to inquiries from prospective customers.

If you apply to us by postal or electronic means and provide personal data, we process this data exclusively for the purpose of initiating a future employment relationship.

2.2.3 Due to legal obligations
Within the scope of our legal obligations, we process your personal data where required or mandated by law. This may include, for example, the disclosure of your data to public authorities in the context of tax or criminal investigations, the analysis of your data to comply with regulatory requirements, or the provision of certain information to legal institutions.

Processing your data on this basis is always necessary. The legal obligation to which we as an organization are subject cannot be affected by any refusal or restriction on your part. We assure you that your personal data will be processed in compliance with the law and will be fully protected.

2.2.4 Based on legitimate interest
We also process your personal data to safeguard our legitimate interests, provided that your interests or fundamental rights and freedoms requiring the protection of your personal data do not override these interests.
Subject to a case-by-case balancing of interests, we generally assume that our legitimate interests prevail in the following (non-exhaustive) processing situations:

  • for ongoing customer support;
  • to inform you about offers of services and products, if we have received your name, email address, or postal address in connection with the provision of our services and/or the sale of our products;
  • to process your inquiries after you contact us;
  • to optimize our processes (e.g., identifying sources of errors), offers, and services;
  • to maintain a customer database within our corporate group to improve customer service;
  • for legal enforcement in cases of suspicion of or actual criminal acts;
  • to ensure the security, confidentiality, and integrity of our IT systems (e.g., through security and effectiveness tests);
  • to process your data for testing IT systems and software products as well as performing migrations to ensure the functionality of new products and the correctness and completeness of migrations;
  • in the event of a security incident affecting your data, we are obliged under Article 33 GDPR to report it without undue delay to the competent data protection supervisory authority. In our legitimate interest to comply with this legal obligation as quickly as possible, it may be necessary to process your personal data as part of the incident investigation. However, no personal data about you will be included in the reports to the supervisory authority;
  • to carry out internal audits, internal reviews, and other control measures (e.g., checks by the data protection or information security officer) to ensure compliance with legal requirements, transparency in our business processes, and continuous improvement. This may require processing documents or files containing your personal data;
  • for corporate management and compliance with our financial and tax obligations (e.g., reporting, audits, internal reviews, and other control measures such as those carried out by tax authorities, external auditors, tax advisors, or certified accountants);
  • to maintain a suppression list in order to implement objections to processing pursuant to Article 21 GDPR.

2.3 From whom do we receive your data?

As a general rule, we process the personal data that you provide to us yourself or that is collected directly from you. In some cases, we may also collect personal data from external sources (see section 2.4); where applicable, we will refer to additional sources in separate sections. Processing is carried out only on the basis of a valid legal basis.

2.4 To whom do we disclose your data?

2.4.1 Companies, representatives, and partners of ipoox
As a general rule, we only disclose your personal data if this is necessary for the establishment, execution, or termination of a contractual or quasi-contractual relationship. In such cases, the data is only shared with companies affiliated with us or with our partners and representatives. Partners and representatives include, in particular, independent commercial agents who distribute our goods and services domestically and internationally. When you contact us, we may, for example, share the information you have provided with the regional ipoox company responsible for you, so that it can offer you our products and services in an optimized manner depending on your needs and the regional context of your request.

The ipoox companies include:

  • ipoox preesorting gmbh, Alfred-Nobel-Straße 13, D-97080 Würzburg
  • ipoox software gmbh, Alfred-Nobel-Straße 13, D-97080 Würzburg

2.4.2 Processors and third parties

On our instructions, your personal data may be processed by processors, provided their involvement is necessary for the processing. In such cases, we ensure that the processing of your personal data complies with the provisions of the GDPR. Processors include, for example, IT service providers, waste disposal companies, etc. In addition, these processors are contractually obliged to either delete the data or return it to us upon termination of their services, in accordance with legal requirements.

Data will only be transferred or disclosed to external recipients if permitted or required by law.

Your data may be disclosed to the following recipients:

  • Public authorities and institutions, as well as law enforcement authorities that receive data on the basis of legal regulations (e.g., tax authorities, auditors, courts, employment agencies, customs authorities, etc.);
  • In the event of legal disputes or suspected criminal activity (e.g., courts, opposing counsel, authorities, contractual partners, consultants, business partners, claim opponents, insofar as this is necessary to protect our rights);
  • Tax advisors, auditors, data protection officers, information security officers, or legal advisors;
  • Payment service providers for the processing of payment transactions (e.g., banks, payment service providers);
  • Debt collection agencies or credit agencies, insofar as this is necessary to enforce our rights;
  • IT and other service providers (e.g., for IT maintenance, cloud services, applications, website support, advertising agencies, destruction of files and data media, credit checks, sanctions list screening, as well as security and guarding services, caterers, call centers);
  • Printing and logistics companies, postal services, delivery services, telecommunications providers, email providers of the recipient, and data media disposal service providers.

2.5 Information on data transfers to third countries

Within our organization, we use services from providers located in countries outside the European Economic Area where no level of data protection comparable to that of the EU exists. When using these services, your personal data may be transferred to and processed in these countries. We ensure that such transfers are carried out only in compliance with Articles 44 et seq. of the General Data Protection Regulation (GDPR) in order to guarantee an adequate level of protection for your data.

2.6 Storage period

Unless a specific or statutory retention period is stated at the time of collection, your personal data will be deleted as soon as it is no longer required for the purpose for which it was collected and no legal retention obligations or other legal grounds for storage exist.

If you assert a valid request for deletion or withdraw consent to data processing, your data will be deleted unless we have other legally permissible grounds for retaining your personal data (e.g., tax or commercial retention obligations). In the latter case, deletion will occur once these reasons no longer apply.

3. Your data subject rights

In accordance with data protection regulations, we would like to inform you about your rights as a data subject. These rights are an essential component of data protection and guarantee your control over your personal data. It is important to us that you are aware of your rights and understand how you can exercise them in order to protect your privacy and the integrity of your data. Below you will find a detailed overview of your rights as well as guidance on how to exercise them if needed.

3.1 Right of access, rectification, and erasure

You have the right to obtain information about your personal data processed by us. This includes information about the source of the data, the recipients, and the purposes of processing. You also have the right to have this data corrected or erased if necessary.

3.2 Right to restriction of processing

You have the right to request the restriction of processing of your personal data. This right applies under the following conditions:

  • Accuracy of the data: If you contest the accuracy of your personal data and verification is required.
  • Unlawful processing: If processing is unlawful, but you oppose erasure and instead request restriction of use.
  • Data no longer needed but required for legal claims: If the controller no longer needs the data for processing purposes, but you require it for the establishment, exercise, or defence of legal claims.
  • Objection to processing: If you have objected to processing pursuant to Article 21(1) GDPR and it is being verified whether the legitimate grounds of the controller override your grounds.

During the restriction period, your data—apart from storage—may only be processed with your consent or for the establishment, exercise, or defence of legal claims, or for the protection of the rights of another natural or legal person, or for important public interest reasons of the Union or a Member State.

3.3 Right to data portability

You have the right, under applicable legal provisions, to receive your personal data that you have provided to us in a structured, commonly used, and machine-readable format. You also have the right to have this data transmitted directly from one controller to another, where technically feasible. This applies where processing is based on consent or a contract and is carried out by automated means.

3.4 Right to object in specific cases

Sie haben das Recht, jederzeit gegen die Verarbeitung Ihrer personenbezogenen Daten Widerspruch einzulegen, wenn diese auf Artikel 6 Absatz 1 lit. f beruht. Diese Bestimmung erlaubt die Datenverarbeitung auf der Grundlage berechtigter Interessen des Verantwortlichen oder eines Dritten, es sei denn, Ihre Interessen oder Grundrechte und Grundfreiheiten, die den Schutz personenbezogener Daten erfordern, überwiegen.

You have the right to object at any time to the processing of your personal data where it is based on Article 6(1)(f) GDPR. This provision allows data processing based on the legitimate interests of the controller or a third party, unless your interests or fundamental rights and freedoms requiring protection of personal data override those interests.

You have the unrestricted right to object at any time to the processing of your personal data for direct marketing purposes, including profiling related to such marketing. Once you object, processing for these purposes will cease. This right is absolute and results in the immediate cessation of the relevant data processing. Individuals also have the right not to be subject to decisions based solely on automated processing that produce legal effects concerning them or similarly significantly affect them.

The right to object also extends to profiling insofar as it is related to direct marketing.

3.5 Withdrawal of your consent to data processing

You have the right to withdraw your consent to processing at any time with effect for the future. However, such withdrawal does not affect the lawfulness of processing carried out prior to the withdrawal.

3.6 Contact for exercising your data subject rights

You may assert your rights and, where applicable, your objection informally by post or email to:
ipoox presorting gmbh
Bereich: Datenschutz
Alfred-Nobel-Straße 13
97080 Würzburg
E-Mail: data-security@ipoox-group.com

3.7 Right to lodge a complaint

If you believe that the processing of your personal data violates data protection law, you have the right under Article 77(1) GDPR to lodge a complaint with a data protection supervisory authority.

4. Data Processing on this Website

4.1 General information on the legal basis for data processing on this website

If you have given your consent to the processing of your data, we process your personal data on the basis of Article 6(1)(a) GDPR or, where special categories of personal data pursuant to Article 9(1) GDPR are processed, Article 9(2)(a) GDPR. If you have expressly consented to the transfer of personal data to third countries, the data processing is also based on Article 49(1)(a) GDPR. If you have consented to the storage of cookies or to the access to information on your terminal device (e.g. via device fingerprinting), the data processing is additionally based on Section 25(1) of the German Telecommunications Digital Services Data Protection Act (TDDDG). Your consent may be withdrawn at any time. If your data is required for the performance of a contract or for the implementation of pre-contractual measures, we process your data on the basis of Article 6(1)(b) GDPR. Furthermore, we process your data where this is necessary for compliance with a legal obligation on the basis of Article 6(1)(c) GDPR. Data processing may also be carried out on the basis of our legitimate interests pursuant to Article 6(1)(f) GDPR. The specific legal basis applicable in each individual case is explained in the following sections of this Privacy Policy.

4.2 External Hosting

We host our website using an external hosting provider. The personal data collected through our website is stored on the hosting provider’s servers. This may include, in particular, IP addresses, contact requests, metadata and communication data, contract data, contact details, names, website access data, and other data generated through the website.

Our hosting provider will process your personal data only to the extent necessary to fulfill its contractual obligations and in accordance with our instructions regarding such data.

We use the following hosting provider:

a4a GmbH
Maybachufer 9
D-12047 Berlin

We have entered into a Data Processing Agreement (DPA) with the service provider for the use of the above-mentioned service. This agreement is required under data protection law and ensures that the service provider processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.

4.3 SSL and/or TLS Encryption

For security reasons and to protect the transmission of confidential content, our website uses SSL and/or TLS encryption. You can recognize an encrypted connection by the fact that the website address begins with “https://” and a padlock symbol is displayed in your browser. When SSL and/or TLS encryption is enabled, the data you transmit to us cannot be read by third parties.

4.4 Cookies

Our website uses so-called “cookies.” Cookies are small data files that do not cause any damage to your device. They are stored on your device either temporarily for the duration of a session (session cookies) or permanently (persistent cookies). Session cookies are automatically deleted at the end of your visit. Persistent cookies remain stored on your device until you delete them yourself or they are automatically deleted by your web browser.

Cookies may be set by us (first-party cookies) or by third-party providers (third-party cookies). Third-party cookies enable the integration of certain services provided by third parties within websites (e.g. cookies used to process payment services).

Cookies serve various functions. Many cookies are technically necessary because certain website functions would not operate properly without them (e.g. the shopping cart function or the display of videos). Other cookies may be used to analyze user behavior or for advertising purposes.

Cookies that are necessary to carry out the electronic communication process, to provide certain functions requested by you (e.g. the shopping cart function), or to optimize the website (e.g. cookies used to measure the website audience) (“necessary cookies”) are stored on the basis of Article 6(1)(f) GDPR, unless another legal basis is specified. The website operator has a legitimate interest in storing necessary cookies to ensure the technically error-free and optimized provision of its services. Where your consent has been requested for the storage of cookies or the use of comparable recognition technologies, the processing is carried out exclusively on the basis of your consent (Article 6(1)(a) GDPR and Section 25(1) of the German Telecommunications Digital Services Data Protection Act (TDDDG)).

You may withdraw your consent at any time. You can configure your browser to notify you whenever cookies are set, to allow cookies only in individual cases, to exclude the acceptance of cookies for certain cases or in general, and to activate the automatic deletion of cookies when closing the browser.

Disabling cookies may limit the functionality of this website. Details of the cookies and services used on this website can be found in this Privacy Policy.

4.5 Consent Management with Borlabs Cookie

Unsere Webseite nutzt die Consent-Technologie von Borlabs Cookie, um Ihre Einwilligung zur Speicherung bestimmter Cookies in Ihrem Browser oder zum Einsatz bestimmter Technologien einzuholen und diese datenschutzkonform zu dokumentieren. Anbieter dieser Technologie ist die Borlabs GmbH, Rübenkamp 32, 22305 Hamburg (im Folgenden Borlabs).

Our website uses the consent management technology provided by Borlabs Cookie to obtain your consent to the storage of certain cookies in your browser or to the use of certain technologies and to document such consent in compliance with data protection regulations.

The provider of this technology is Borlabs GmbH, Rübenkamp 32, 22305 Hamburg, Germany (hereinafter referred to as “Borlabs”). When you visit our website, a Borlabs cookie is stored in your browser, which documents the consents you have given as well as any withdrawal of consent. This data is not transmitted to the provider of Borlabs Cookie. The data collected will be stored until you request its deletion, delete the Borlabs cookie yourself, or the purpose for storing the data no longer applies. Mandatory statutory retention periods remain unaffected. Further details on data processing by Borlabs Cookie can be found at: https://de.borlabs.io/kb/welche-daten-speichert-borlabs-cookie/

The use of Borlabs Cookie consent management technology is carried out in order to obtain the legally required consents for the use of cookies. The legal basis for this is Article 6(1)(c) GDPR.

4.6 Server-Log-Files

The provider of this website automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. This information includes:

  • Browser type and browser version
  • Operating system used
  • Referrer URL
  • Hostname of the accessing device
  • Time of the server request
  • IP address

This data is not combined with data from other sources.

The collection of this data is based on Article 6(1)(f) GDPR. The website operator has a legitimate interest in ensuring the technically error-free presentation and optimization of its website; for this purpose, server log files must be collected.

4.7 Google Maps

This website uses the Google Maps map service. The provider is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland. This service enables us to integrate map material into our website.

In order to use the functions of Google Maps, it is necessary to store your IP address. This information is generally transmitted to a Google server in the United States and stored there. The provider of this website has no influence on this data transfer. If Google Maps is activated, Google may use Google Fonts for the purpose of ensuring a consistent display of fonts. When Google Maps is accessed, your browser loads the required web fonts into your browser cache in order to display texts and fonts correctly.

The use of Google Maps is in the interest of providing an attractive presentation of our online services and making it easier to find the locations indicated on our website. This constitutes a legitimate interest pursuant to Article 6(1)(f) GDPR. Where consent has been requested, processing is carried out exclusively on the basis of Article 6(1)(a) GDPR and Section 25(1) of the German Telecommunications Digital Services Data Protection Act (TDDDG), insofar as the consent includes the storage of cookies or access to information on the user’s device (e.g. device fingerprinting) within the meaning of the TDDDG. Consent may be withdrawn at any time. The transfer of data to the United States is based on the Standard Contractual Clauses of the European Commision. Further information can be found here:

https://privacy.google.com/businesses/gdprcontrollerterms/ and
https://privacy.google.com/businesses/gdprcontrollerterms/sccs/.
Further information on how user data is handled can be found in Google’s Privacy Policy:
https://policies.google.com/privacy?hl=en
The company is certified under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the United States intended to ensure compliance with European data protection standards when processing data in the United States. Every company certified under the DPF undertakes to comply with these data protection standards. Further information can be obtained from the provider via the following link:
https://www.dataprivacyframework.gov/participant/5780.

For more information on how user data is handled, please see Google’s Privacy Policy: https://policies.google.com/privacy?hl=de.

The company is certified under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the United States intended to ensure compliance with European data protection standards when processing data in the United States. Every company certified under the DPF undertakes to comply with these data protection standards. Further information can be obtained from the provider via the following link: https://www.dataprivacyframework.gov/participant/5780.

4.8 Google Fonts

This website uses so-called Google Fonts, provided by Google, to ensure a consistent display of fonts. When you access a page, your browser loads the required fonts into your browser cache in order to display texts and fonts correctly. For this purpose, the browser you use must establish a connection to Google’s servers.

As a result, Google becomes aware that this website has been accessed via your IP address. The use of Google Fonts is based on Article 6(1)(f) GDPR. The website operator has a legitimate interest in ensuring the consistent presentation of the typeface on its website. Where consent has been requested, processing is carried out exclusively on the basis of Article 6 (1)(f) GDPR. The website operator has a legitimate interest in ensuring the consistent presentation of the typeface on its website. Where consent has been requested, processing is carried out exclusively on the basis of Article 6 (1)(a) GDPR and Section 25(1) of the German Telecommunications Digital Services Data Protection Act (TDDDG), insofar as the consent includes the storage of cookies or access to information on the user’s device (e.g. device fingerprinting) within the meaning of the TDDDG.

Consent may be withdrawn at any time. If your browser does not support Google Fonts, a standard font from your computer will be used.

Further information about Google Fonts can be found at:
https://developers.google.com/fonts/faq and in Google’s Privacy Policy: https://policies.google.com/privacy?hl=en

The company is certified under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the United States intended to ensure compliance with European data protection standards when processing data in the United States. Every company certified under the DPF undertakes to comply with these data protection standards. Further information can be obtained from the provider via the following link: https://www.dataprivacyframework.gov/participant/5780.

5. Data Processing as Part of the Application Process

We offer you the opportunity to apply for a position with us (e.g. by email or by post). Below, we inform you about the scope, purpose, and use of the personal data collected from you as part of the application process. We assure you that the collection, processing, and use of your data are carried out in accordance with applicable data protection laws and all other relevant legal provisions, and that your data will be treated as strictly confidential.

Please note that we only accept applications submitted by email via the mailbox hr@ipoox-group.com.

To ensure a compliant application process, please always submit your application through the channels provided.

5.1 Scope and Purpose of Data Collection

If you submit an application to us, we process the personal data associated with your application (e.g. contact and communication data, application documents, notes taken during interviews, etc.) to the extent necessary to make a decision regarding the establishment of an employment relationship. The legal basis for this is Article 6(1)(b) GDPR (general initiation of a contractual relationship) in conjunction with Section 26 of the German Federal Data Protection Act (BDSG) under German law (initiation of an employment relationship). If you claim reimbursement of travel expenses, we process the related personal data (e.g. bank details, details of the travel expenses claimed, etc.). The legal basis for this processing is Article 6(1)(c) GDPR (compliance with legal obligations). Where you have provided us with your consent, the legal basis is Article 6(1)(a) GDPR. You may withdraw your consent at any time with effect for the future. Within our company, your personal data will only be disclosed to persons involved in processing your application.

If you provide links to your profiles on social networks in your application, we reserve the right to view these profiles as part of the selection process.

If you provide us with information about your previous employers or name a reference person, we may contact them with your express consent (Article 6(1)(a) GDPR) in order to obtain a recommendation or assessment of your person. This is based on our legitimate interest in incorporating such references into the decision-making process (Article 6(1)(f) GDPR).).

5.2 Job Application Portals, Recruitment Agencies, and the Federal Employment Agency

In certain cases, we engage recruitment agencies or use job application portals for the purpose of recruiting employees, publishing job advertisements, or directly approaching candidates. Depending on the individual case and the respective channel used, the above-mentioned data may be collected directly from you or obtained and/or transmitted to us via the respective recruitment agency or platform. In addition, we receive applicant profiles with contact details from the Federal Employment Agency pursuant to Section 38(2) of the German Social Code, Book III (SGB III).

5.3 Online Interviews

As part of the application process, we offer candidates the opportunity to conduct job interviews via a video conferencing tool. This enables contactless communication and helps overcome geographical distances. Video or audio material will not be recorded or stored at any time. Applicants are free to disable the camera function before or during the interview.

An applicant may refuse to participate in a video interview without providing any reason. In this case, a mutually acceptable alternative will be sought. When using a video conferencing tool, the transfer of data to a third country (in particular the United States) cannot be ruled out. The legal basis for processing is consent pursuant to Article 6(1)(a) GDPR. Consent may be withdrawn at any time.

5.4 Data Retention Period

If we are unable to offer you a position, you reject a job offer, or you withdraw your application, we reserve the right to retain the data you have provided based on our legitimate interests (Article 6(1)(f) GDPR) for up to six months after the completion of the application process (rejection or withdrawal of the application). After this period, the data will be deleted and any physical application documents will be destroyed. The retention serves in particular to provide evidence in the event of a legal dispute. If it is foreseeable that the use of the data will be required beyond the six-month period (e.g. due to an impending or ongoing legal dispute), the data will only be deleted once the purpose for the continued retention no longer applies.

Longer retention may also take place if you have given your consent (Article 6(1)(a) GDPR) or if statutory retention obligations prevent the deletion of the data.

5.5 Addition to the Candidate Pool

If we are unable to offer you a position, we may have the option of including you in our applicant pool. If you are included in the applicant pool, all documents and information provided as part of your application will be transferred to the applicant pool in order to contact you in the event of suitable vacancies.

Inclusion in the applicant pool takes place exclusively on the basis of your explicit consent (Article 6(1)(a) GDPR). Providing consent is voluntary and has no connection with the ongoing application process. You may withdraw your consent at any time. In this case, your data will be deleted from the applicant pool without delay, unless statutory retention obligations apply.

Data stored in the applicant pool will be permanently deleted no later than two years after consent has been granted.

6. Data Processing in Other Cases

6.1 Customer Relationship Management System (CRM)

We use a proprietary, locally operated Customer Relationship Management (CRM) system to manage customer and supplier data.

Our CRM system enables us, among other things, to manage existing and potential customers as well as customer contacts, and to organize sales and communication processes. The use of the CRM system also enables us to analyze our customer-related processes. Customer data is stored exclusively on our own servers.

The use of our CRM system is based on Art. 6(1)(f) GDPR. Our corporate group has a legitimate interest in ensuring efficient customer management and customer communication. Where corresponding consent has been requested, processing is carried out exclusively on the basis of Art. 6(1)(a) GDPR and Section 25(1) TDDDG, insofar as the consent covers the storage of cookies or access to information stored on the user’s device (e.g., device fingerprinting) within the meaning of the TDDDG. Consent may be withdrawn at any time.

6.2 Inquiry by email or telephone

When you contact us by email or telephone, your inquiry, including all personal data arising from it (name, inquiry, attachments), will be stored and processed in our CRM and email systems for the purpose of handling your request.

The processing of this data is based on Art. 6(1)(b) GDPR, insofar as your inquiry is related to the performance of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the effective handling of inquiries addressed to us (Art. 6(1)(f) GDPR) or on your consent (Art. 6(1)(a) GDPR), where such consent has been requested; consent may be withdrawn at any time.

The data you provide to us through contact requests will remain with us until you request its deletion, withdraw your consent to the storage of the data, or the purpose for storing the data no longer applies (e.g., after your request has been fully processed). Mandatory statutory provisions, in particular statutory retention periods, remain unaffected.

6.3 Processing of personal data in connection with audio and video conferences

We use online conferencing tools, among other methods, to communicate with our customers. The specific tools we use are listed below. When you communicate with us via video or audio conference over the Internet, your personal data is collected and processed by us and by the provider of the respective conferencing tool.

The conference tools collect all data that you provide/use in order to use the tools (email address and/or your telephone number). In addition, the conference tools process the duration of the conference, the start and end time of participation in the conference, the number of participants, and other “context information” related to the communication process (metadata).

Furthermore, the provider of the tool processes all technical data required to facilitate online communication. This includes, in particular, IP addresses, MAC addresses, device IDs, device type, operating system type and version, client version, camera type, microphone or speaker information, as well as the type of connection.

If content is exchanged, uploaded, or otherwise provided within the tool, such content is also stored on the servers of the respective tool providers. Such content includes, in particular, cloud recordings, chat/instant messages, voicemails, uploaded photos and videos, files, whiteboards, and other information shared during the use of the service.

Please note that we do not have full control over the data processing operations carried out by the tools we use. Our ability to influence such processing is primarily determined by the corporate policies of the respective provider. Further information on data processing by the conference tools can be found in the privacy notices of the respective tools used, which are listed below this text.

6.3.1 Purpose and legal bases
The conference tools are used to communicate with prospective or existing contractual partners or to provide certain services to our customers (Art. 6(1)(b) GDPR). Furthermore, the use of these tools serves to generally simplify and accelerate communication with us and our company (legitimate interest pursuant to Art. 6(1)(f) GDPR). Where consent has been requested, the respective tools are used on the basis of this consent; consent may be withdrawn at any time with effect for the future.

6.3.2 Retention period
The data collected directly by us through the video and conference tools will be deleted from our systems as soon as you request its deletion, withdraw your consent to the storage of the data, or the purpose for storing the data no longer applies. Stored cookies remain on your device until you delete them. Mandatory statutory retention periods remain unaffected.

We have no influence over the retention period of your data that is stored by the operators of the conference tools for their own purposes. For further details, please contact the respective operators of the conference tools directly.

6.3.3 Conference tools – Microsoft Teams

We use Microsoft Teams. The provider is Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. For details on data processing, please refer to Microsoft Teams’ privacy statement: https://privacy.microsoft.com/de-de/privacystatement.

The company is certified under the “EU-U.S. Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the United States intended to ensure compliance with European data protection standards when processing data in the United States. Every company certified under the DPF undertakes to comply with these data protection standards. Further information can be obtained from the provider via the following link: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt0000000KzNaAAK&status=Active

We have concluded a Data Processing Agreement (DPA) for the use of the above-mentioned service.

6.4 Data sharing (Nextcloud®)

For the secure exchange of data with our business partners, we use the Nextcloud solution. Nextcloud is free software developed in PHP and based on an ownCloud fork, which is operated on our own servers.

Nextcloud enables us to provide an upload and download area on our system through which you can securely upload and download documents and files. The content transmitted in this process is stored exclusively on our servers in Germany.

The following types of data may be processed as part of the use of the service:

  • Master data: e.g. first name, last name, email address
  • Access data: e.g. username, password (encrypted)
  • Communication data: e.g. IP address, access timestamps, log information
  • File content: all documents and files uploaded or downloaded by you
  • Metadata: e.g. file name, file size, upload/download timestamp, user ID

The use of the service is based on Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure, reliable, and user-friendly handling of data exchange with our business partners. Where we obtain your consent in individual cases, processing is carried out on the basis of Art. 6(1)(a) GDPR. This consent may be withdrawn at any time with effect for the future.

6.5 Newsletter distribution to existing customers

If you use services provided by us and provide your email address in this context, we may subsequently use this email address to send you newsletters, provided that we have informed you of this in advance. In such a case, the newsletter will only contain direct advertising for our own similar goods or services. You may unsubscribe from receiving this newsletter at any time. For this purpose, each newsletter contains a corresponding link. The legal basis for sending the newsletter in this case is Art. 6(1)(f) GDPR in conjunction with Section 7(3) UWG (German Act Against Unfair Competition).

After you unsubscribe from the newsletter mailing list, your email address may be stored by us in a blacklist in order to prevent future mailings to you. The data stored in the blacklist will only be used for this purpose and will not be combined with other data. This serves both your interests and our interest in complying with the legal requirements for sending newsletters (legitimate interest pursuant to Art. 6(1)(f) GDPR). Storage in the blacklist is not limited in time. You may object to this storage if your interests outweigh our legitimate interest.

6.6 Video surveillance at our premises

For the protection of our organisation’s property, employees, customers, and suppliers, as well as for the prevention and investigation of theft and vandalism, the assessment of property damage, and regular functional checks, video surveillance is carried out at our premises. The retention period is 72 hours. Recordings required for the purposes of preserving evidence will be stored for as long as necessary for legal enforcement purposes.

  • The recordings may be accessed by the service provider (data processor) during maintenance of the system.
  • In the context of criminal investigations, the data may be disclosed to authorities and/or legal advisors commissioned by us.

The legal basis for this processing is Article 6(1)(f) of the General Data Protection Regulation (GDPR) (overriding legitimate interest). Our legitimate interest lies in improving the protection of the company’s property, as well as the property of customers, suppliers, and employees, against burglary, theft, and vandalism, safeguarding our property rights, and asserting claims against third parties.

6.7 Sending product information

If we provide you with information as part of pre-contractual measures or an existing business relationship, we only process the data that is necessary for this purpose. This includes:

  • Personal details (first name and last name);
  • Company name;
  • Contact details (telephone number, email address)

6.8 Christmas and New Year greetings

At the end of the year, we may send Christmas and New Year greetings to customers and business partners. In order to send you these greetings, your name and address will be collected and processed.

be collected and processed.
The processing of this data is based on a business purpose pursuant to Art. 6(1)(f) GDPR. The controller has a legitimate interest in expressing appreciation for and fostering customer and business relationships.

Your data will not be disclosed to third parties.

If you do not wish to receive greeting cards from us, you may object to receiving them. You can submit your objection to us without providing any reasons, as described in the section “Data Subject Rights”. Your data will then no longer be used for this purpose.

6.9 Credit checks

When purchasing on account, where we make advance payments on your behalf, we may carry out a creditworthiness check (scoring). For this purpose, we transmit the data you have provided (e.g. company name, address, or bank details) to a credit reference agency. Based on this data, the probability of payment default is determined. In the event of an excessive risk of payment default, we may refuse the respective payment method.

The creditworthiness check is carried out on the basis of the performance of the contract (Art. 6(1)(b) GDPR) and to prevent payment defaults (legitimate interest pursuant to Art. 6(1)(f) GDPR). Where consent has been obtained, the creditworthiness check is carried out on the basis of this consent (Art. 6(1)(a) GDPR); consent may be withdrawn at any time.

7.1 Data processing by social networks

We maintain publicly accessible profiles on social networks. The social networks we use in detail are listed below.

Social networks are generally able to comprehensively analyze your user behavior when you visit their websites or websites that contain integrated social media content (e.g. like buttons or advertising banners). Visiting our social media presences triggers numerous data processing operations relevant to data protection. In particular:

  • If you are logged into your social media account and visit our social media presence, the operator of the social media platform may associate this visit with your user account. However, your personal data may also be collected if you are not logged in or do not have an account with the respective social media platform. In this case, data collection may take place, for example, through cookies stored on your device or by collecting your IP address.
  • With the help of the data collected in this way, the operators of social media platforms may create user profiles in which your preferences and interests are stored. This enables interest-based advertising to be displayed to you both within and outside the respective social media presence. If you have an account with the respective social network, interest-based advertising may be displayed on all devices on which you are or have been logged in.
  • Please also note that we are not able to fully track all processing operations carried out by social media platforms. Depending on the provider, additional processing activities may therefore be carried out by the operators of the social media platforms. For further details, please refer to the terms of use and privacy policies of the respective social media platforms.

7.2 Legal basis

The purpose of our social media presences is to ensure the broadest possible presence on the internet. This constitutes a legitimate interest within the meaning of Art. 6 (1)(f) GDPR. The analysis processes initiated by the social networks may be based on different legal bases, which must be specified by the operators of the social networks (e.g. consent pursuant to Art. 6(1)(a) GDPR).

7.3 Controller and data subject rights

If you visit one of our social media presences (e.g. Facebook), we are jointly responsible with the operator of the social media platform for the data processing operations triggered by this visit. In principle, you may assert your rights (access, rectification, erasure, restriction of processing, data portability, and the right to lodge a complaint) both against us and against the operator of the respective social media platform (e.g. Facebook).

Please note that, despite our joint responsibility with the operators of social media platforms, we do not have full control over the data processing operations carried out by these platforms. Our ability to influence such processing is primarily determined by the policies of the respective provider.

7.4 Retention period

The data collected directly by us via the social media presence will be deleted from our systems as soon as you request its deletion, withdraw your consent to the storage of the data, or the purpose for storing the data no longer applies. Stored cookies remain on your device until you delete them. Mandatory statutory provisions – in particular statutory retention periods – remain unaffected.

We have no influence over the retention period of your data that is stored by the operators of social networks for their own purposes. For further details, please contact the operators of the social networks directly (e.g. in their privacy notices, see below).

7.5 Social networks in detail

7.5.1 Facebook
We have a profile on Facebook. The provider of this service is Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland (hereinafter referred to as “Meta”). According to Meta, the data collected may also be transferred to the United States and other third countries.

You can adjust your advertising settings independently in your user account. To do so, please click on the following link and log in: https://www.facebook.com/settings?tab=ads

The transfer of data to the United States is based on the EU Commission’s Standard Contractual Clauses. Further details can be found here: https://www.facebook.com/legal/EU_data_transfer_addendum
and https://de-de.facebook.com/help/566994660333381

For further details, please refer to Facebook’s privacy policy: https://www.facebook.com/about/privacy/

The company is certified under the “EU-U.S. Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the United States intended to ensure compliance with European data protection standards when processing data in the United States. Every company certified under the DPF undertakes to comply with these data protection standards. Further information can be obtained from the provider via the following link:
https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt0000000GnywAAC&status=Active

7.5.2 X (former Twitter)
We use the short message service X. The provider is Twitter International Company, One Cumberland Place, Fenian Street, Dublin 2, D02 AX07, Ireland.

You can adjust your X privacy settings independently in your user account. To do so, please click on the following link and log in: https://twitter.com/personalization

The transfer of data to the United States is based on the EU Commission’s Standard Contractual Clauses. Further details can be found here: https://gdpr.twitter.com/en/controller-to-controller-transfers.html

For further details, please refer to X’s privacy policy: https://twitter.com/de/privacy

7.5.3 Instagram
We have a profile on Instagram. The provider of this service is Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.

The transfer of data to the United States is based on the EU Commission’s Standard Contractual Clauses. Further details can be found here: https://www.facebook.com/legal/EU_data_transfer_addendum,
https://privacycenter.instagram.com/policy/, and https://de-de.facebook.com/help/566994660333381

For details on how your personal data is handled, please refer to Instagram’s privacy policy:

The company is certified under the “EU-U.S. Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the United States intended to ensure compliance with European data protection standards when processing data in the United States. Every company certified under the DPF undertakes to comply with these data protection standards. Further information can be obtained from the provider via the following link:
https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt0000000GnywAAC&status=Active

7.5.4 XING
We have a profile on XING. The provider of this service is New Work SE, Dammtorstraße 30, 20354 Hamburg, Germany. For details on how your personal data is handled, please refer to XING’s privacy policy: https://privacy.xing.com/de/datenschutzerklaerung

7.5.5 LinkedIn
We have a profile on LinkedIn. The provider of this service is LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland. LinkedIn uses advertising cookies.

If you wish to deactivate LinkedIn advertising cookies, please use the following link:

The transfer of data to the United States is based on the EU Commission’s Standard Contractual Clauses. Further details can be found here: https://www.linkedin.com/legal/l/dpa and https://www.linkedin.com/legal/l/eu-sccs

For details on how your personal data is handled, please refer to LinkedIn’s privacy policy: https://www.linkedin.com/legal/privacy-policy