
This privacy policy describes how we collect, use and process your personal data and how we thereby comply with our legal obligations towards you. The protection of your data is important to us. We have therefore made it our mission to handle your data responsibly and to protect and safeguard it.
Of course, we comply with the statutory provisions of the General Data Protection Regulation (GDPR), the Federal Data Protection Act (BDSG), the Telecommunications Digital Services Data Protection Act (TDDDG), the Swiss Federal Act on Data Protection (FADP), as well as other applicable data protection provisions.
This privacy policy applies to the personal data of visitors to our website – customers, suppliers, applicants and any other persons who may be concerned – and informs you, as a user, about the nature, scope and purpose of the collection and use of personal data by us as the controller for this website.
Insofar as this privacy notice applies to users in Switzerland or our processing otherwise has effects in Switzerland, the following information shall also constitute information pursuant to the Swiss FADP. For reasons of readability, the following information partly uses terms from the GDPR. For Switzerland, corresponding terms shall be construed mutatis mutandis in accordance with the FADP; in particular, the GDPR term “processing” corresponds to “processing” within the meaning of the FADP. Legal bases under the GDPR are stated insofar as the GDPR is applicable. For processing operations that are subject exclusively to the Swiss FADP, an explicit statement of individual legal bases is generally not required; the relevant factors in this respect are, in particular, the principles of lawfulness, transparency, purpose limitation, proportionality, data security, as well as the other requirements of the FADP.
The controller responsible for processing your personal data on these web pages is
VENDOSOFT GmbH
represented by its managing director Björn Franz Anton Orth
Rudolf-Diesel-Ring 10
82266 Inning a. Ammersee
Germany
With regard to the website vendosoft.ch or other services we provide for users in Switzerland, the above details regarding the controller shall apply accordingly, unless a separate controller is specified in an individual case. For enquiries from Switzerland, you can contact us using the contact options stated above.
By way of derogation, the controller of the website www.vendosoft.at is:
VENDOSOFT GmbH & Co.KG
represented by Vendosoft Verwaltungs Gmbh, which is represented by its managing director Björn Franz Anton Orth
Mentlgasse 1
6020 Innsbruck
Austria
I. General information on data processing
- Scope & purpose of the processing of personal data
As a user of this website, we generally process your personal data only to the extent that this is necessary to provide a functional website and our content and services: - Legal basis and justification for the processing of personal data
Insofar as the GDPR is applicable, we base the processing of your personal data in particular on the legal bases listed below: Consent (Article 6(1)(a) GDPR), performance of a contract or implementation of pre-contractual measures (Article 6(1)(b) GDPR), compliance with legal obligations (Article 6(1)(c) GDPR), and safeguarding of legitimate interests (Article 6(1)(f) GDPR). Insofar as special categories of personal data are processed, this is done only on the basis of a relevant statutory authorisation or your explicit consent.
Insofar as the Swiss FADP is applicable, we state the purposes, categories of personal data, recipients, and disclosures abroad in this privacy notice. Under the FADP, an explicit allocation of individual processing operations to legal bases is generally not required. In this case, we process personal data in compliance with the applicable principles of the FADP, in particular lawfully, in good faith, transparently, for specified purposes, proportionately, and with appropriate data security.
Handling of personal data
According to Article 4(1) GDPR, personal data is “any information relating to an identified or identifiable natural person.” A natural person is considered identifiable if they can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
Personal data that we process
We then collect, use and/or disclose this personal data where this is permitted by law or where you, as a user, consent to the collection of data.
Customer data:
We use personal information about prospective customers and customers to ensure that the contractual arrangements between us can be properly implemented (e.g. for submitting offers, fulfilling deliveries, etc.) and to ensure a smooth business relationship. For this purpose, we use the following categories of personal data:
-
- First and last name;
- Business email address;
- Business phone number;
- Position in the company;
- Business address;
- Bank details.
Where the GDPR is applicable, the legal basis is Article 6(1)(b) GDPR insofar as the processing is necessary for the implementation of pre-contractual measures or for the performance of a contract, Article 6(1)(c) GDPR insofar as statutory obligations exist, and Article 6(1)(f) GDPR on the basis of our legitimate interest in initiating, performing, managing and safeguarding our customer relationships. Where the Swiss FADP is applicable, we process this data for the stated purposes in compliance with the principles of the FADP.
Supplier data:
We mainly use our suppliers’ personal data to ensure that the contractual arrangements between us can be properly implemented and thus enable a smooth business relationship. Secondly, to ensure compliance with statutory requirements. For this purpose, we use the following categories of personal data:
-
- First and last name;
- Business email address;
- Business phone number;
- Position in the company;
- Business address;
- Bank details.
Where the GDPR is applicable, the legal basis is Article 6(1)(b) GDPR insofar as the processing is necessary for the implementation of pre-contractual measures or for the performance of a contract, Article 6(1)(c) GDPR insofar as statutory obligations exist, and Article 6(1)(f) GDPR on the basis of our legitimate interest in initiating, performing, managing and safeguarding our supplier and business partner relationships. Where the Swiss FADP is applicable, we process this data for the stated purposes in compliance with the principles of the FADP.
Applicant data:
The reason for using personal information about applicants is to assess whether your application to VENDOSOFT GmbH matches the requirements of our vacant positions. All the information we have about you, your skills and your objectives helps us to offer you a tailored job opportunity. For this purpose, we use the following categories of personal data:
-
- Contact details in your applicant profile (this includes, in particular, first and last name, country, email address, telephone number);
- Information from application forms (this includes, in particular, salary expectations, your motivation, and, where applicable, information regarding disability (only insofar as relevant for the advertised position));
- Application documents (this includes, in particular, CV, covering letter, information on professional development, qualifications and language skills);
- Results of online procedures (this includes, in particular, video interviews);
- References you provide to us.
Where the GDPR is applicable, the legal basis is Section 26(1) BDSG and Article 6(1)(b) GDPR insofar as the processing is necessary for the decision on the establishment of an employment relationship or for the implementation of pre-contractual measures. Insofar as special categories of personal data are processed, in particular voluntary information regarding a disability, this is done only in accordance with Article 9(2)(b) GDPR in conjunction with Section 26(3) BDSG or, where applicable, on the basis of your explicit consent pursuant to Article 9(2)(a) GDPR. Where the Swiss FADP is applicable, we process applicant data for the purposes of carrying out the application procedure in compliance with the principles of the FADP.
Access data/server log files
If you use the website for information purposes only, i.e. if you do not register or otherwise transmit information to us, we collect only the personal data that your browser transmits to our server. The access data includes:
-
- Name of the webpage accessed;
- File, date and time of access;
- Volume of data transferred;
- Message indicating successful access;
- Browser type and version;
- User’s operating system;
- Referrer URL (the previously visited page);
- (shortened) IP address;
- requesting provider.
We use this log data only for technically necessary statistical analyses for the purposes of operating, securing and optimising our website. However, we reserve the right to review the log data subsequently if there is a justified suspicion of unlawful use based on specific indications.
Where the GDPR is applicable, the legal basis is Article 6(1)(f) GDPR on the basis of our legitimate interest in the secure, stable and functional operation of our website, in error analysis, and in the detection of misuse and attacks. Insofar as technically necessary information is read from or stored on your end device in this context, this is also carried out on the basis of Section 25(2) no. 2 TDDDG. Where the Swiss FADP is applicable, we process this data for the stated technical and security-related purposes in compliance with the principles of the FADP.
Disclosure of personal data:
We may disclose your personal data, where applicable and in accordance with local laws and regulations, to the following categories of recipients:
- External service providers who provide services on our behalf (including solicitors, auditors and accountants),
- Providers of outsourced services and storage providers with whom we have entered into a corresponding data processing agreement pursuant to Article 28 GDPR (including email dispatch services, mailing houses, telemarketing providers, IT service providers).
- The overview below lists key service providers that we use for the general operation of our website and our business processes. Insofar as individual third-party providers, tracking, analytics, payment, review, social media or security services are described separately in this privacy notice, the respective recipients, purposes, data categories and legal bases are additionally set out in the relevant individual sections. The overview is therefore not to be understood as an exhaustive list of all recipients.
| Service provider | Service | Country of domicile |
| mwbsc GmbH | Web design | Germany |
| IT-Beratung Ralf Bub GmbH | Hosting, ERP system, web shop | Germany |
| CleverReach GmbH & Co.KG | Newsletter service | Germany |
In addition, we may transfer data to public authorities and institutions where there is a statutory or regulatory obligation to do so.
Further recipients of data may be those bodies to which you have given us your consent to disclose data. Further information on this is provided below in this privacy notice.
Protection of personal data:
We take all reasonable and appropriate measures to protect the personal information stored by us against misuse, loss or unauthorised access. This applies to internal storage on our systems, includes securing our systems against external access, and extends to the secure transfer of data to the third parties referred to above.
II. Cookies and tracking technologies
In addition to the data mentioned above, cookies are stored on your computer when you use our website. Cookies are small text files that are stored on your hard drive by the browser you use and enable certain information to be transmitted to us as the party that sets the cookie. Cookies cannot run programmes or transmit viruses to your computer. They are used to make the online offering more user-friendly and effective overall. In addition to cookies, we also use other tracking and analytics tools to improve our online offering and our marketing measures (collectively referred to below as “cookies”).
We use different types of cookies on our website:
- Strictly necessary cookies
- Functional cookies
- Marketing cookies
- Statistics cookies
Depending on the settings of our consent management tool, the following services in particular may be used: strictly necessary services such as WPML, Trusted Shops, TrustIndex, Cloudflare Turnstile/Captcha and the Cookie Consent Manager CCM19; analytics and statistics services such as WhatConverts, Microsoft Clarity, Microsoft services, Meta Pixel, LinkedIn Analytics, Hotjar, Google Tag Manager, Google DoubleClick, Google Analytics 4 and Google Analytics; advertising and marketing services such as LinkedIn Ads; and social media services such as LinkedIn plugins. Details of the respective services can be found in the other sections as well as in the information provided in the consent management tool.
Some of these cookies are technically necessary for the operation of our website, whereas other cookies serve to improve our online offering. The use of strictly necessary cookies is based on Article 6(1)(f) GDPR and Section 25(2) no. 2 TDDDG. Non-essential cookies are only set if you have given your consent for their use in each case (Article 6(1)(a) GDPR, Section 25(1) TDDDG) or have clicked “Agree” within our consent management tool. Your consent covers the storage of the cookie on your end device, the transmission of the information collected by cookies, and the associated processing of personal data. You can change the settings you have made at any time by clicking the “Reject” button. This allows you to withdraw consent you have given with effect for the future. Further information on the cookies and tracking technologies used can be found within our consent management tool under “More information” and in our privacy policy.
Some of these cookies transmit personal data to companies in the United States. If you consent to the use of such cookies in each individual case or click “Accept all cookies”, you accept the processing of your personal data in the United States on the basis of the European Commission’s adequacy decision under Article 45 GDPR.
You can configure your browser settings according to your wishes and, for example, refuse the acceptance of third-party cookies or all cookies. Please note that you may then not be able to use all functions of this website. For more detailed information on preventing the use of third-party cookies and other tracking technologies, please refer to the following sections on the services used.
You can also restrict or completely prevent the setting of cookies via the relevant browser settings, or arrange for cookies to be automatically deleted when you close the browser window.
Information on how to delete cookies in the most commonly used browsers or change cookie settings can be found here:
The provision of personal data is neither required by law nor contractually, nor is it necessary for the conclusion of a contract. However, failure to provide such data may mean that you cannot use our website, or cannot use it in full.
Google Analytics
With your consent pursuant to Article 6(1)(a) GDPR and Section 25(1) TDDDG, we use third-party cookies to learn more about your browsing behaviour (web tracking). This website uses functions of the web analytics service Google Analytics. The provider in the EU is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The parent company of Google Ireland Limited is Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
By setting the cookie, Google is enabled to analyse the use of our website. Each time one of the individual pages of this website is accessed, which is operated by the controller and on which a Google Analytics component has been integrated, following the granting of consent the internet browser on the data subject’s end device is prompted by the relevant Google Analytics component to transmit data to Google for the purposes of online analysis.
As part of this technical procedure, the following data is collected, among other things:
- Your IP address (in shortened form)
- Your user behaviour
- Your approximate location
- The pages you visit
The recipient of the data is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The information generated by the cookies about your use of this website is generally also transmitted to a Google server in the USA and stored there. The European Commission has confirmed the adequacy of the level of data protection under the EU-U.S. Data Privacy Framework, under which Google LLC is certified. The transfer to the USA is therefore permitted under Article 45 GDPR.
The retention period depends on the settings (properties) used. Where the new Google Analytics 4 properties are used, the retention period of your usage data is limited to 14 months.
We also have the option of restarting the retention period with each of your visits to our website, provided you revisit it within the original retention period.
Where the Swiss FADP is applicable, we process this data for the stated purposes in compliance with the principles of the FADP.
More information on how Google Analytics handles usage data can be found in Google’s privacy policy: https://support.google.com/analytics/answer/6004245.
You can withdraw your consent at any time with effect for the future, without giving reasons, by opening our consent management tool and changing your selection there.
You can also prevent the storage of cookies by adjusting the settings of your browser software; however, please note that in this case you may not be able to use all functions of this website to their full extent.
You have the option to disable the settings for personalised advertising at https://support.google.com/ads/answer/2662922?hl=de.
You can also prevent Google from processing your data by downloading and installing the browser plug-in available at the following link: https://tools.google.com/dlpage/gaoptout?hl=de.
We have concluded a data processing agreement with Google and implement the strict requirements of European data protection law when using Google Analytics. More information about the “Data Processing Addendum” concluded between us and Google can be found here: https://support.google.com/analytics/answer/3379636?hl=de&utm_id=ad.
As part of this processing, Google is entitled to engage sub-processors. A list of the sub-processors used by Google can be found at: https://privacy.google.com/businesses/subprocessors/.
Google DoubleClick
With your consent pursuant to Article 6(1)(a) GDPR and Section 25(1) TDDDG, we use Google DoubleClick, a service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google DoubleClick is used for the delivery, management and performance measurement of online advertising, as well as to prevent the same advert from being displayed multiple times. In particular, cookie IDs, IP addresses, device and browser information, referrer URLs, interactions with adverts, and information about pages visited may be processed. The data may also be transferred to Google LLC in the USA. Where the Swiss FADP is applicable, we process this data for the stated purposes in compliance with the principles of the FADP. You can withdraw your consent at any time with effect for the future via our consent management tool.
The retention period for cookies and comparable technologies set by Google DoubleClick can be found in the information provided in our consent management tool. In all other respects, the data processed in this context will be deleted as soon as it is no longer necessary for the stated purposes, you withdraw your consent, or statutory retention obligations do not prevent deletion.
Microsoft Clarity and Microsoft services
With your consent pursuant to Article 6(1)(a) GDPR and Section 25(1) TDDDG, we use Microsoft Clarity and, where applicable, other Microsoft services to analyse the use of our website and to optimise our online offering. The provider is Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland; the parent company is Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA. Microsoft Clarity can, in particular, record mouse movements, clicks, scrolling behaviour, interactions with page elements, device and browser information, screen resolution, approximate location, IP address, and usage and session data, and analyse this in pseudonymised form. A transfer to the USA cannot be ruled out. Where the Swiss FADP is applicable, we process this data for the stated purposes in compliance with the principles of the FADP. You can withdraw your consent at any time with effect for the future via our consent management tool.
The retention period for cookies and comparable technologies set by Microsoft Clarity and Microsoft services can be found in the information provided in our consent management tool. In all other respects, analytics and session data will be deleted or anonymised as soon as it is no longer necessary for the stated purposes, you withdraw your consent, or statutory retention obligations do not prevent deletion.
Meta Pixel
With your consent pursuant to Article 6(1)(a) GDPR and Section 25(1) TDDDG, we use the Meta Pixel of Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. The Meta Pixel enables us to measure the effectiveness of our advertising measures on Meta platforms, create target audiences for adverts, and deliver interest-based advertising. In particular, the IP address, device and browser information, cookie and pixel IDs, referrer URL, pages visited, interactions with our website, and information about conversion events may be processed. The data may also be transferred to Meta Platforms, Inc. in the USA. Where the Swiss FADP is applicable, we process this data for the stated purposes in compliance with the principles of the FADP. You can withdraw your consent at any time with effect for the future via our consent management tool.
The retention period for cookies and comparable technologies set via the Meta Pixel can be found in the information provided in our consent management tool. In all other respects, the data processed in this context will be deleted or anonymised as soon as it is no longer necessary for the stated purposes, you withdraw your consent, or statutory retention obligations do not prevent deletion.
WhatConverts
With your consent pursuant to Article 6(1)(a) GDPR and Section 25(1) TDDDG, we use WhatConverts to analyse leads, contact enquiries and conversions. The provider is WhatConverts, 50 Glenlake Parkway, Suite 350, Atlanta, GA 30328, USA. The service may, in particular, process information about contact forms, calls, chat or lead interactions, referrer URLs, campaign parameters, cookie IDs, IP addresses, and device and browser information. The processing is used to assign enquiries to marketing channels, evaluate them and optimise our advertising measures. A transfer to the USA may take place; the information on transfers of data to third countries applies. Where the Swiss FADP is applicable, we process this data for the stated purposes in compliance with the principles of the FADP. You can withdraw your consent at any time with effect for the future via our consent management tool.
The retention period for cookies and comparable technologies set by WhatConverts can be found in the information provided in our consent management tool. In all other respects, lead and conversion data will be deleted or anonymised as soon as it is no longer required for the analysis and attribution of the relevant enquiry, you withdraw your consent, or statutory retention obligations do not prevent deletion.
Google Ads
We place adverts in Google Search and on other websites via the Google Ads service. Google Ads is an online advertising service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The legal basis for the processing of your personal data in connection with the use of Google Ads is your consent within the meaning of Article 6(1)(a) GDPR and Section 25(1) TDDDG. Where the Swiss FADP is applicable, we process this data for the stated purposes in compliance with the principles of the FADP.
Google Ads enables us to evaluate the effectiveness of our adverts within the Google network and to optimise our advertising measures. If you reach our website via a Google advert placed by us, a cookie will be set in your browser which enables Google and us to recognise your browser. If you visit certain pages on our website and the cookie stored on your end device has not yet expired, Google and we can recognise that you clicked on the advert and were redirected to that page.
Google provides us with this data in the form of statistical evaluations without any reference to individuals. This allows us to identify which of the advertising measures used are particularly effective.
The recipient of the data is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The information generated by the cookies is generally also transmitted to a Google server in the USA and stored there. The European Commission has confirmed the adequacy of the level of data protection under the EU-U.S. Data Privacy Framework, under which Google LLC is certified. The transfer to the USA is therefore permitted under Article 45 GDPR.
You can withdraw your consent at any time with effect for the future, without giving reasons, by opening our consent management tool and changing your selection there.
You can also prevent the storage of cookies by adjusting the settings of your browser software; however, please note that in this case you may not be able to use all functions of this website to their full extent.
Google Tag Manager
We use Google Tag Manager on our website. Google Tag Manager is a solution provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, which enables us to manage website tags via an interface. The legal basis for the processing of your personal data in connection with the use of Google Tag Manager is your consent within the meaning of Article 6(1)(a) GDPR and Section 25(1) TDDDG. Google Tag Manager is not a cookie in the strict sense, but rather ensures the direct triggering of other tags, which may in turn collect data that it does not access. However, when triggering a tag, Google may process personal data, such as the IP address or online identifiers. In this context, it cannot be ruled out that Google will also transmit this information to a server in a third country. The transfer of your data to Google servers in the USA is permitted on the basis of the adequacy decision adopted by the European Commission with regard to the EU-U.S. Data Privacy Framework, under which Google LLC is certified, pursuant to Article 45 GDPR. Where the Swiss FADP is applicable, we process this data for the stated purposes in compliance with the principles of the FADP.
Google Tag Manager itself does not store any data. The retention period of your data depends on the cookies and tools deployed via Google Tag Manager.
More information on data protection and security when using Google Tag Manager can be found at https://support.google.com/tagmanager/answer/9323295 and https://policies.google.com/privacy?hl=de.
You can withdraw your consent at any time with effect for the future, without giving reasons, by opening our consent management tool and changing your selection there.
We have concluded a data processing agreement with Google and implement the strict requirements of European data protection law when using Google Tag Manager. Google processes the data on our behalf in order to trigger the stored tags and display services on our website. More information about the “Data Processing Addendum” concluded between us and Google can be found here: https://business.safety.google/adsprocessorterms/.
As part of this processing, Google is entitled to engage sub-processors. A list of the sub-processors used by Google can be found at: https://privacy.google.com/businesses/subprocessors/.
Google Signals
We use Google Signals. When you visit our website, Google Analytics collects, among other things, your location, search history and YouTube history, as well as demographic data (visitor data). This data may be used for personalised advertising through Google Signals. If you have a Google account, the visitor data from Google Signals is linked by Google to your Google account and used for personalised advertising messages. The data is also used to generate anonymised statistics on our users’ behaviour.
Google Signals is used only to the extent that you have consented to the use of Google Analytics and the corresponding processing. The legal basis is your consent pursuant to Article 6(1)(a) GDPR and Section 25(1) TDDDG. You can withdraw your consent at any time with effect for the future via our consent management tool. Where the Swiss FADP is applicable, we process this data for the stated purposes in compliance with the principles of the FADP.
WPML
We use WPML to provide multilingual content on our website. WPML may set technically necessary cookies in order to store the language you have selected and to provide the website in the appropriate language version. This is used to provide our website in a technically proper and user-friendly manner on the basis of Article 6(1)(f) GDPR and Section 25(2) No. 2 TDDDG. Where the Swiss FADP is applicable, we process this data in order to provide the desired language version in compliance with the principles of the FADP.
The technically necessary cookies set by WPML are stored only for as long as is necessary to store your language setting and to provide the desired language version. The specific duration can be found in the information provided in our consent management tool.
Cookie Consent Manager CCM19
We use the Cookie Consent Manager CCM19 to manage and document your consents and refusals regarding the use of cookies and comparable technologies. In particular, your consent decision, the date and time of your selection, technical information about the browser and end device used, and a pseudonymous identifier may be processed. Its use is technically necessary in order to implement your data protection settings and to be able to demonstrate compliance. The legal basis is Article 6(1)(c) and (f) GDPR and Section 25(2) No. 2 TDDDG. Where the Swiss FADP is applicable, we process this data for the transparent management of your data protection settings and to fulfil our accountability obligations in compliance with the principles of the FADP.
The consent and refusal decisions stored in connection with CCM19 are stored for as long as is necessary to document your selection and to fulfil statutory accountability obligations. The specific retention period of the cookies used can be found in the information provided in our consent management tool.
Trusted Shops
We may integrate services from Trusted Shops on our website, in particular to display trust and rating elements and, where applicable, to enable customer reviews. The provider is Trusted Shops SE, Subbelrather Straße 15C, 50823 Cologne, Germany. When accessing the relevant elements, the IP address, the date and time of access, device and browser information, and information about the use of the integrated element may, in particular, be processed. Where the integration is technically necessary, it is carried out on the basis of Article 6(1)(f) GDPR and Section 25(2) No. 2 TDDDG; where non-essential cookies or comparable technologies are used beyond this, processing is carried out on the basis of your consent pursuant to Article 6(1)(a) GDPR and Section 25(1) TDDDG. Where the Swiss FADP is applicable, we process this data for the stated purposes in compliance with the principles of the FADP.
The retention period for cookies and comparable technologies set by Trusted Shops can be found in the information provided in our consent management tool. In all other respects, the data processed in this context will be deleted or anonymised as soon as it is no longer necessary for displaying the trust and rating elements or for the respective customer review, you withdraw your consent, or statutory retention obligations do not prevent deletion.
Cloudflare Turnstile/Captcha
We use Cloudflare Turnstile/Captcha, in particular as part of newsletter registration, to protect our forms against automated entries, spam and misuse. The provider is Cloudflare Germany GmbH, Rosental 7, 80331 Munich, Germany; the technical service may also be provided by Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA. Cloudflare Turnstile/Captcha uses technical characteristics to check whether an entry is made by a natural person with a sufficient degree of probability. In particular, the IP address, device and browser information, operating system, referrer URL, interaction data with the form, timestamps, and technical verification identifiers may be processed. Where the GDPR is applicable, the service is used on the basis of our legitimate interest in the security of our website and in preventing misuse pursuant to Article 6(1)(f) GDPR, and as a technically necessary service pursuant to Section 25(2) No. 2 TDDDG. Where the Swiss FADP is applicable, we process this data for the stated security purposes in compliance with the principles of the FADP. A transfer of data to the USA cannot be ruled out; the information on transfers of data to third countries applies. Cloudflare Turnstile/Captcha is not used for advertising purposes.
The technical data processed in connection with Cloudflare Turnstile/Captcha is stored only for as long as is necessary to carry out the security check, to prevent misuse, and to ensure system security. The specific duration of any technically necessary cookies or verification identifiers can be found in the information provided in our consent management tool.
Hotjar
With your consent pursuant to Article 6(1)(a) GDPR and Section 25(1) TDDDG, we use Hotjar’s tracking and analytics services to better understand our users’ needs and to optimise the offering and experience on this website. Hotjar is a service provided by Hotjar Limited, Dragonara Business Centre, 5th Floor, Dragonara Road, Paceville St Julian’s STJ 3141, Malta. Using Hotjar’s technology, we gain a better understanding of our users’ experiences (e.g. how much time users spend on which pages, which links they click, what they like and what they do not like, etc.), which helps us align our offering with our users’ feedback. Hotjar uses cookies and other technologies to collect data about our users’ behaviour and their end devices. Where the Swiss FADP is applicable, we process this data for the stated purposes in compliance with the principles of the FADP.
In this context, the following data may be processed and stored by Hotjar:
- IP address of the device (collected and stored only in anonymised form during your use of the website),
- screen size,
- device type (unique device identifiers),
- information about the browser used,
- location (country only),
- preferred language for displaying our website.
Hotjar stores this information on our behalf in a pseudonymised user profile. Hotjar is contractually prohibited from selling the data collected on our behalf.
The data collected by Hotjar is stored by Hotjar for 365 days.
You can withdraw your consent to the setting of cookies at any time with effect for the future, without giving reasons, by opening our consent management tool and changing your selection there.
When visiting a website that uses Hotjar, you can prevent Hotjar from collecting your data at any time by going to our opt-out page https://www.hotjar.com/legal/ and clicking “Disable Hotjar”.
Further information can be found under the “About Hotjar” section at https://help.hotjar.com/hc/de/articles/360045420794-Datenschutz-FAQs.
Matelso
With your consent pursuant to Article 6(1)(a) GDPR and Section 25(1) TDDDG, we use a service provided by Matelso GmbH, Heilbronner Straße 150, 70191 Stuttgart, on our website. This is a tool for tracking telephone calls, which uses cookies for the analysis and evaluation of user behaviour. For this purpose, Matelso integrates telephone numbers on our website, enabling us to carry out further analyses of the calling behaviour of our website visitors. If you call a number set up by Matelso for us, the caller’s telephone number, the number called, the date, the time and the duration of the call are, in particular, stored. If we are able to do so on the basis of existing customer information, we also link this data with the associated address record. Where the Swiss FADP is applicable, we process this data for the stated purposes in compliance with the principles of the FADP.
In addition, the following data is also processed when using Matelso:
- the website from which you accessed our online offering (referrer URL),
- remote user agent,
- document path,
- browser information,
- cookie IDs.
As part of this call tracking, personal data is transmitted to Matelso servers and stored there. We have concluded a data processing agreement with Matelso pursuant to Article 28 GDPR. The relevant information is processed by Matelso in accordance with our instructions and stored only on servers within the EU. Your data will be deleted as soon as its processing is no longer necessary for the purposes for which it was collected.
You can also prevent the collection and transmission of the aforementioned personal data and the processing of this data by withholding your number before calling us or calling from an anonymous number. You can also install a JavaScript blocker, e.g. www.noscript.net or www.ghostery.com, to prevent the collection of other website analytics data. Further information on data protection when using Matelso can be accessed via the following links: https://knowledge.matelso.com/de/matelso-cookies and https://www.matelso.com/de/privacy-statement.
You can withdraw your consent to the setting of cookies at any time with effect for the future, without giving reasons, by opening our consent management tool and changing your selection there.
LinkedIn Insight Tag
We use the LinkedIn Insight Tag on our website. The provider of this service is LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland. The legal basis for the processing of your personal data in connection with the use of the LinkedIn Insight Tag is the consent you have given within the meaning of Article 6(1)(a) GDPR and Section 25(1) TDDDG. Where the Swiss FADP is applicable, we process this data for the stated purposes in compliance with the principles of the FADP.
The LinkedIn Insight Tag is an analytics and conversion tracking tool that enables us to understand the behaviour of visitors to our website and, on this basis, to optimise our advertising measures within the LinkedIn network. In particular, this allows us to see whether users carry out certain actions on our website after clicking on a LinkedIn advertisement. In addition, the LinkedIn Insight Tag enables us to display interest-based advertising (retargeting) on the LinkedIn platform.
In this context, the following data is processed, among other things:
- your IP address,
- the website from which you accessed our online offering (referrer URL),
- device and browser characteristics,
- time of access.
The recipient of the data is LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland. As a rule, the information collected is also transferred to servers of LinkedIn Corporation, 1000 W Maude Ave, Sunnyvale, CA 94085, USA, in the United States and processed there. The transfer of your data to LinkedIn servers in the United States is permitted on the basis of the European Commission’s adequacy decision pursuant to Article 45 GDPR in respect of the EU-U.S. Data Privacy Framework, under which LinkedIn Corporation is certified.
According to LinkedIn, the direct identifiers collected by LinkedIn are deleted within 7 days. Pseudonymised data is generally deleted within 180 days.
Further information on LinkedIn’s handling of personal data can be found in LinkedIn’s privacy policy: https://de.linkedin.com/legal/privacy-policy?.
You can withdraw your consent at any time with effect for the future, without giving reasons, by opening our consent management tool and changing your selection there.
LinkedIn Analytics and LinkedIn Ads
Where LinkedIn Analytics and LinkedIn Ads are listed separately in our consent management tool, these are functions of LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland, which can be used in connection with the LinkedIn Insight Tag. LinkedIn Analytics is used to evaluate the use of our website and the impact of our content and campaigns. LinkedIn Ads is used to deliver, measure and optimise advertising within the LinkedIn network and, where applicable, for retargeting. In particular, IP address, cookie IDs, device and browser information, referrer URL, time of access, interactions with our website and information about conversion events may be processed. The legal basis is your consent pursuant to Article 6(1)(a) GDPR and Section 25(1) TDDDG. Where the Swiss FADP is applicable, we process this data for the stated purposes in compliance with the principles of the FADP. You can withdraw your consent at any time with effect for the future via our consent management tool.
The retention period for cookies and comparable technologies set by LinkedIn Analytics and LinkedIn Ads can be found in the information provided in our consent management tool. In addition, the deletion periods specified in the section on the LinkedIn Insight Tag apply; where data is processed beyond this, it will be deleted or anonymised as soon as it is no longer necessary for the stated analytics, advertising and retargeting purposes, you withdraw your consent, or statutory retention obligations do not prevent deletion.
LinkedIn plugin
Social media elements from LinkedIn may be integrated on our website. The provider is LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland. If you access a page with a LinkedIn element or interact with such an element, data such as IP address, device and browser information, referrer URL, pages accessed and interaction data may be transmitted to LinkedIn. If you are logged in to LinkedIn, LinkedIn may associate your visit to our website with your LinkedIn account. Where consent is required for this purpose, the service is used on the basis of your consent pursuant to Article 6(1)(a) GDPR and Section 25(1) TDDDG. Where the Swiss FADP is applicable, we process this data for the stated purposes in compliance with the principles of the FADP. You can withdraw your consent at any time with effect for the future via our consent management tool.
The retention period for cookies and comparable technologies set by LinkedIn is determined by LinkedIn’s information and the information provided in our consent management tool. Data that we process in connection with the integration of the LinkedIn plugin will be deleted as soon as it is no longer necessary for the display and use of the plugin, you withdraw your consent, or statutory retention obligations do not prevent deletion.
III. Contacting us
When you contact us (for example via the contact form, the call-back service or by email), your details will be stored for the purpose of handling your enquiry and in case follow-up questions arise. In particular, your contact details and the content you submit as part of the message are processed. For enquiries relating to contracts, Article 6(1)(b) GDPR is the legal basis for the processing. For other enquiries, the processing is based on our legitimate interest in providing a contact option at all times and handling your enquiries, pursuant to Article 6(1)(f) GDPR. In addition, the date and time of the contact, and for the contact and quotation forms also your IP address, are processed. This processing is based on our legitimate interest pursuant to Article 6(1)(f) GDPR in carrying out abuse monitoring of our contact options. The personal data is stored only for as long as is necessary to handle the contact request.
IV. Advertising
-
Existing customers
As a rule, we have a legitimate interest in using data of our existing customers for marketing purposes for our own goods or services that are similar to goods and services already purchased. We collect the following data from our existing customers for our own marketing purposes: First name, surname, email address, telephone number (business).The legal basis for the use of personal data for marketing purposes is Article 6(1)(f) GDPR.
-
Advertising with consent
If you are not an existing customer of ours, or if we advertise goods and services that do not originate from us or are not similar to goods or services you have previously obtained from us, we process your data for marketing purposes only on the basis of your explicit consent for these purposes pursuant to Article 6(1)(a) GDPR.
Information on the right to object
You may object at any time, free of charge and with effect for the future, to the use of your personal data for the above advertising purposes using the contact details provided above.
If you object, your data will be blocked for further processing for advertising purposes. Please note that, in exceptional cases, advertising material may still be sent for a short time after we receive your objection. This is due to the necessary lead time for selection for technical reasons and does not mean that we have not implemented your objection.
Newsletter sign-up
If you complete and submit our newsletter web form, by clicking the “Send” button displayed underneath you consent to the data you entered being transmitted to us. For this purpose, we use the service provider mentioned above, CleverReach GmbH & Co. KG, as a processor for sending the newsletter. In this context, we use the so-called double opt-in procedure. You will first receive an email with a confirmation link. You will only be subscribed to our newsletter after clicking this link. The data entered will be stored and used exclusively to process your request. This specifically means sending a monthly email newsletter that includes our “Offer of the Month”. Your email address will be transmitted to our newsletter dispatch service provider (see “Disclosure of data”).
The legal basis for sending the newsletter is your consent pursuant to Article 6(1)(a) GDPR. Where tracking technologies are used as part of the newsletter, in particular to measure opens or clicks, this also takes place only on the basis of your consent pursuant to Article 6(1)(a) GDPR and Section 25(1) TDDDG. The documentation of the sign-up, the double opt-in procedure and any withdrawal is carried out on the basis of our legitimate interest in being able to prove lawful subscription and unsubscription pursuant to Article 6(1)(f) GDPR. Where the Swiss FADP is applicable, we process this data for sending the newsletter and documenting your sign-up in compliance with the principles of the FADP.
To protect the newsletter sign-up against misuse, automated entries and spam, we use Cloudflare Turnstile/Captcha. Technical information may be processed for this purpose, in particular IP address, device and browser information, interaction data, referrer URL and timestamps, in order to check whether the entry is made by a natural person. Where the GDPR is applicable, this is used on the basis of our legitimate interest in security and abuse prevention pursuant to Article 6(1)(f) GDPR and as a technically necessary service under Section 25(2) no. 2 TDDDG. Where the Swiss FADP is applicable, we process this data to ensure the security of the newsletter sign-up and to prevent misuse, in compliance with the principles of the FADP.
You have the right at any time to withdraw your consent to the storage, processing and use of your data with effect for the future by sending us a message e.g. by email.
Data deletion and retention period
Your personal data will be deleted or blocked as soon as the purpose for storage no longer applies. Data may also be stored beyond this if this is provided for by laws or other legal provisions that are binding on us. The data will also be blocked or deleted when a retention period prescribed by the above legal provisions expires, unless further storage of the data is necessary for the conclusion of a contract or for contract performance. Applicant data will be deleted no later than six months after completion of the application procedure, provided that no employment relationship has been established with us.
3. Advertising using customer reviews
We integrate customer reviews on Google on our websites. For this purpose, we use the Trustindex.io service provided by Trustindex Ltd. TrustIndex is listed in our consent management tool as a technically necessary service insofar as the service is required to display the review and trust elements integrated on our website. When accessing the relevant content, the following data may be processed in particular: IP address, date and time of access, device and browser information, and information on the use of the integrated element. Where the GDPR is applicable, the legal basis is our legitimate interest in presenting authentic customer reviews and trust elements pursuant to Article 6(1)(f) GDPR, and Section 25(2) no. 2 TDDDG insofar as the storage of, or access to, information on the end device is technically necessary for this purpose. Where the Swiss FADP is applicable, we process this data for the display of customer reviews and trust elements in compliance with the principles of the FADP. Further information can be found at https://www.trustindex.io/privacy-policy. The reviews are reproduced unchanged from our public Google profile. No filtering or weighting is carried out. Publication includes the date of your review, your name (possibly also the company name, photo/logo), as well as your rating and the review text. You can only change or delete your public review via your own Google profile. The retention period for technically necessary cookies or comparable technologies can be found in the information provided in our consent management tool; otherwise, the data we process will be deleted as soon as it is no longer necessary for displaying the review and trust elements or statutory retention obligations prevent deletion.
V. Data transfer to third countries
In the course of our business activities, it is possible that we may also pass on your personal data to recipients in countries outside the European Economic Area or outside Switzerland, where the level of data protection is not the same as in your home country. If this is the case and there is neither an adequacy decision of the European Commission pursuant to Article 45 GDPR nor a recognition of adequate data protection under Swiss law, we take additional measures to ensure an adequate level of data protection for the transfer of data to these countries. This may be achieved in particular by entering into EU Standard Contractual Clauses and, where required, by providing additional safeguards or adapting those safeguards to the requirements of the Swiss FADP. If you would like further information about these security measures, you can contact us at any time using the contact options listed above.
VI. Contractual services in connection with online store
We process your personal data only to the extent necessary to process your orders in the online shop or to handle your contact requests.
In doing so, we only ever process the personal data you provide to us, such as your name, your contact details, payment details and order data.
The data is processed for the purpose of contract performance and the implementation of pre-contractual measures on the legal basis of Article 6(1)(b) GDPR. In addition, in order to process your email address in the event of a purchase via our websites/applications, we are obliged under statutory requirements of the German Civil Code (BGB) to send an electronic order confirmation (Article 6(1)(c) GDPR).
To provide you with the greatest possible convenience, we offer you the permanent storage of your personal data in a password-protected customer account/user account.
Creating the customer account is required for placing an order and, where the GDPR is applicable, is carried out for contract performance and/or for the implementation of pre-contractual measures on the basis of Article 6(1)(b) GDPR. Once a customer account has been set up, no further data entry is required. You can also view and change the data stored about you in your customer account at any time. Where the Swiss FADP is applicable, we process this data for the fulfilment and handling of the order and for the provision of the customer account in compliance with the principles of the FADP.
In addition to the data requested when placing an order, you must specify a password of your choice in order to set up a customer account. Together with your email address, this is used to access your customer account. Please treat your personal access data confidentially and, in particular, do not make it accessible to any unauthorised third party. You have the option to delete your customer account at any time. Please note, however, that this does not automatically result in the deletion of the data viewable in the customer account if you have ever placed an order with us. Your data will be deleted automatically after expiry of the commercial and tax law retention obligations applicable to us. The legal basis for this data processing is Article 6(1)(c) GDPR and Article 6(1)(f) GDPR.
Insofar as we do not use your data for advertising purposes, we store the data collected for contract performance until expiry of the statutory and/or any contractual warranty and guarantee rights. After expiry of this period, we retain the information required under commercial and tax law relating to the contractual relationship for the legally prescribed periods. For this period, the data will be processed again solely in the event of an audit by the tax authorities.
VII. Payment service providers
We only transfer data to third parties in the context of the order for the purpose of payment processing.
If you do not wish to do so, you may choose payment by invoice as your payment method at any time instead; in this case, we do not transmit any data to the payment service providers listed below.
PAYPAL
PayPal is an online payment service provider. Payments are processed via so-called PayPal accounts, which are virtual private or business accounts. In addition, PayPal offers the option of processing virtual payments by credit card or by SEPA direct debit if a user does not have a PayPal account. A PayPal account is managed via an email address. PayPal enables you to initiate online payments to third parties and to receive payments. PayPal also performs escrow functions and offers buyer protection services.
PayPal’s European operating company is PayPal (Europe) S.à.r.l. & Cie. S.C.A., 22-24 Boulevard Royal, 2449 Luxembourg, Luxembourg.
If, during the ordering process in our online shop, the data subject selects “PayPal Checkout” as the payment option, the personal data required for payment processing is automatically transferred to PayPal. The transfer is necessary in order to provide the payment method you selected and to process the payment.
The personal data transferred to PayPal generally includes first name, surname, address, email address, IP address, telephone number, or other data necessary for payment processing. Personal data that is related to the respective order is also necessary to process the purchase contract.
The purpose of transferring the data is payment processing and fraud prevention. The transfer is carried out on the basis of contract performance pursuant to Article 6(1)(b) GDPR and, insofar as personal data is transferred beyond this, on the basis of our legitimate interests in secure payment processing and fraud prevention pursuant to Article 6(1)(f) GDPR. Where the Swiss FADP is applicable, we transfer this data for the purposes stated, in compliance with the principles of the FADP.
The personal data exchanged between PayPal and us may, in some cases, be transferred by PayPal to credit reference agencies. The purpose of this transfer is identity and creditworthiness checks. PayPal is the controller for this.
PayPal may disclose personal data to affiliated companies and service providers or subcontractors insofar as this is necessary to fulfil the contractual obligations or the data is to be processed on PayPal’s behalf.
Insofar as PayPal processes personal data under its own responsibility, you may have the respective applicable data subject rights vis-à-vis PayPal. Any restriction or revocation vis-à-vis PayPal does not affect personal data that must necessarily be processed, used or transmitted for payment processing in accordance with the contract.
PayPal’s applicable privacy policy can be accessed at https://www.paypal.com/de/webapps/mpp/ua/privacy-full.
VIII. Your rights
When your personal data is processed, you have the following rights, which we would like to inform you about below.
Right of access
Upon request, we will confirm whether personal data relating to you is being processed. If this is the case, you have the right to be informed about the following:
- the purpose(s) of the data processing;
- the categories of processed data;
- where applicable, the recipients or categories of recipients to whom data is disclosed due to legal obligations or contractual relationships, in particular recipients in third countries;
- the envisaged retention period or, if this is not possible, the criteria used to determine that period;
- the existence of a right to rectification or erasure of personal data relating to you, or to restriction of processing by us, or a right to object to such processing;
- the existence of a right to lodge a complaint with the supervisory authority where the personal data is not collected from the data subject: All available information about the origin of the data;
- where the personal data has not been collected directly from you, all available information about the origin of the data;
- the existence of automated decision-making, including profiling, and meaningful information about the logic involved as well as the significance and the envisaged consequences of such processing for the data subject;
- in the event of transfer to a third country or to an international organisation, the appropriate safeguards relating to the transfer.
Upon request, you will receive a copy of the data collected from you and processed. This is generally provided free of charge.
Right to rectification
You have the right to request the rectification without undue delay of inaccurate personal data relating to you. You have the right, taking into account the purposes of the processing, to request the completion of incomplete personal data — including by means of a supplementary statement.
Right to erasure (the so-called right to be forgotten)
Upon request and/or after performance or termination of the contract with us, your personal data will be deleted without delay, unless retention or documentation obligations (e.g. under commercial and tax law) prevent this or unless safeguarding the controller’s legitimate interests would be jeopardised.
A right to erasure exists under the following conditions:
- The personal data was collected for, or otherwise processed for, purposes for which it is no longer necessary.
- You withdraw your consent on which the processing was based pursuant to Article 6(1)(a) GDPR or Article 9(2)(a) GDPR, and there is no other legal basis for the processing.
- You object to the processing pursuant to Article 21(1) GDPR and there are no overriding legitimate grounds for the processing, or you have objected to the processing pursuant to Article 21(2) GDPR.
- The personal data has been processed unlawfully.
- Erasure of the personal data is necessary for compliance with a legal obligation under Union law or the law of the Member States to which the controller is subject.
- The personal data was collected in relation to the offer of information society services pursuant to Article 8(1) GDPR (consent was given by a child)
Right to restriction of processing (blocking)
Under the following conditions, you have the right to request restriction of processing, i.e. the blocking of your personal data, for the processing:
- You contest the accuracy of the personal data, for a period enabling us to verify the accuracy of the personal data.
- The processing is unlawful, you oppose the erasure of the personal data and request the restriction of the use of the personal data instead.
- The controller no longer needs the personal data for the purposes of the processing, but you require it for the establishment, exercise or defence of legal claims.
- You have objected to the processing pursuant to Article 21(1) GDPR and it has not yet been determined whether the controller’s legitimate grounds override those of the user.
Right to data portability (data portability)
Upon request, your data can be made available in a structured, commonly used and machine-readable format for you and for a subsequent service provider, in order to enable a rapid transfer. This applies in any event insofar as the processing is based on consent pursuant to Article 6(1)(a) GDPR or Article 9(2)(a) GDPR or on a contract pursuant to Article 6(1)(b) GDPR, and the processing is carried out by automated means.
Right to object
You also have the right to object to the processing of your personal data. Where processing is carried out for the purposes of direct marketing, you may exercise this right at any time. Otherwise, you may also have the right, on grounds relating to your particular situation, to object at any time to the processing of personal data relating to you. This applies insofar as the processing is carried out on the basis of Article 6(1)(e) or (f) GDPR. To exercise this right to object, you can send us an informal message using the contact options stated above.
Right to withdraw consent
Pursuant to Article 7(3) GDPR, you have the right to withdraw any consent you have given at any time, without giving reasons. Your withdrawal shall apply only with future effect. Withdrawing your consent does not affect the lawfulness of the processing carried out on the basis of the consent up to the point of withdrawal.
Right to lodge a complaint with the supervisory authority
If you believe that there has been a breach of data protection provisions, you have the right to lodge a complaint with the competent supervisory authority. For us, this is, for example, the Bavarian State Office for Data Protection Supervision (Bayerisches Landesamt für Datenschutzaufsicht).
Where the Swiss FADP is applicable, you have rights under the FADP, in particular rights of access, data disclosure or data transfer, as well as rectification, erasure or restriction and/or cessation of certain processing of personal data. You may also contact the Swiss Federal Data Protection and Information Commissioner (FDPIC). The details and conditions of these rights are governed by the applicable data protection law in each case.
If you wish to withdraw consent, request erasure, or request changes, rectifications or updates to your data, please let us know – for example via the contact channels set out at the beginning of this Privacy Policy.
IX. Changes
We reserve the right to adapt security and data protection measures insofar as this becomes necessary due to technical or legal developments. In such cases, we will also amend this information accordingly. Therefore, please refer to the latest version of our privacy notices.
X. Definitions
For better understanding, we would like to provide you below with the definitions from the GDPR, insofar as they are relevant to our privacy notices. Where the Swiss FADP is applicable, these terms shall be understood accordingly within the meaning of the FADP; in particular, “processing” corresponds to “Bearbeitung” of personal data under Swiss law.
| Supervisory authority | “Supervisory authority” means an independent public authority established by a Member State pursuant to Article 51 GDPR. |
| Processor | A processor is a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller. |
| Third party | Third party means a natural or legal person, public authority, agency or body other than the data subject, controller, processor and persons who, under the direct authority of the controller or processor, are authorised to process personal data. |
| Restriction of processing | Restriction of processing is the marking of stored personal data with the aim of restricting its future processing (in the sense of blocking) |
| Consent | Consent means any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which they, by a statement or by a clear affirmative action, signify agreement to the processing of personal data relating to them. |
| Recipient | Recipient means a natural or legal person, public authority, agency or another body, to which personal data is disclosed, whether a third party or not. However, public authorities which may receive personal data in the framework of a particular inquiry in accordance with Union law or the law of Member States shall not be regarded as recipients. |
| Personal data | Personal date means any information relating to an identified or identifiable natural person (hereinafter “data subject”). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
Personal data, in simplified terms, is individual information about the personal or factual circumstances of a specific or identifiable natural person, i.e. not legal persons, such as a German limited liability company (GmbH). Personal data includes, in particular, details such as name, address, email address, as well as the IP address. |
| Profiling | Profiling means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements. |
| Pseudonymisation | Pseudonymisation means the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures to ensure that the personal data is not attributed to an identified or identifiable natural person. |
| Controller | Controller means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data. Where the purposes and means of such processing are determined by Union law or Member State law, the controller or the specific criteria for its nomination may be provided for by Union law or Member State law. |
| Processing | Processing means any operation or set of operations which is performed on personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction. |
Last updated: 07/2026