Data Protection & Privacy Policy
1. Data Protection at a Glance
General Information:
The following information provides a simple overview of what happens to your personal data when you visit this website. Personal data refers to all data that can be used to identify you personally. Detailed information on data protection can be found in our full Privacy Policy listed below.
Data Collection on This Website
Who is responsible for data collection on this website?
The data processing on this website is carried out by the website operator. The operator’s contact details can be found in the website’s legal notice (Impressum).
How do we collect your data?
Some data is collected when you provide it to us. This may include data you enter into a contact form.
Other data is collected automatically or with your consent when you visit the website. This primarily includes technical data (e.g., internet browser, operating system, or time of page access). This data is collected automatically as soon as you enter this website.
What do we use your data for?
Part of the data is collected to ensure the proper functioning of the website. Other data may be used to analyze user behavior.
What rights do you have regarding your data?
You have the right to receive information, free of charge, about the origin, recipients, and purpose of your stored personal data at any time. You also have the right to request the correction or deletion of your data. If you have given your consent to data processing, you may withdraw it at any time for the future. Additionally, you have the right to request the restriction of the processing of your personal data under certain circumstances. Furthermore, you have the right to lodge a complaint with the competent supervisory authority.
You may contact us at any time at the address provided in the legal notice for further questions about data protection.
Analytics and Third-Party Tools
Your browsing behavior may be statistically analyzed when visiting this website. This is primarily done using analytics programs.
Detailed information about these analytics programs can be found in the following Privacy Policy.
2. Hosting and Content Delivery Networks (CDN)
External Hosting
This website is hosted by an external service provider (host). The personal data collected on this website is stored on the servers of the host. This may include IP addresses, contact inquiries, meta and communication data, contract data, contact details, names, website access logs, and other data generated via the website.
The use of the host is for the purpose of fulfilling our contractual obligations to potential and existing customers (Art. 6(1)(b) GDPR) and in the interest of a secure, fast, and efficient provision of our online services by a professional provider (Art. 6(1)(f) GDPR).
Our host will only process your data to the extent necessary to fulfill its service obligations and follow our instructions regarding this data.
Conclusion of a Data Processing Agreement
To ensure data processing in compliance with data protection regulations, we have entered into a data processing agreement with our host.
3. General Information and Mandatory Disclosures
Data Protection
The operators of this website take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with statutory data protection regulations and this Privacy Policy.
When you use this website, various personal data will be collected. Personal data is data that can be used to identify you personally. This Privacy Policy explains what data we collect and what we use it for. It also explains how and for what purpose this occurs.
Please note that data transmission over the Internet (e.g., communication by email) may have security vulnerabilities. A complete protection of the data against access by third parties is not possible.
Notice Regarding the Data Controller
The data controller responsible for the processing of data on this website is:
Wulf Johannsen KG GmbH & Co.
Marie-Curie-Str. 19
24145 Kiel-Wellsee
Germany
Phone: +49 431 58795-0
Email: info@wulf-johannsen.de
The controller is the natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data (e.g., names, email addresses, etc.).
Statutory Data Protection Officer
We have appointed a Data Protection Officer for our company:
CompliPro GmbH
René Floitgraf
Frankenstraße 34
52223 Stolberg
Germany
Phone: +49 2402 9245980
Email: dsb@complipro.de
Notice on Data Transfers to the USA
Our website integrates tools from companies based in the United States. When these tools are active, your personal data may be transmitted to the respective companies' servers located in the U.S. We would like to point out that the United States is not considered a country with an adequate level of data protection as defined by EU data protection law.
U.S. companies are legally obliged to provide personal data to security authorities without allowing you, as the data subject, any legal recourse. Therefore, it cannot be ruled out that U.S. authorities (e.g., intelligence agencies) may process, analyze, and store your data located on U.S. servers for surveillance purposes. We have no influence over these processing activities.
Revocation of Your Consent to Data Processing
Many data processing operations are only possible with your explicit consent. You may revoke any previously granted consent at any time. The legality of data processing carried out prior to the revocation remains unaffected by the revocation.
RIGHT TO OBJECT TO DATA COLLECTION IN SPECIAL CASES AND TO DIRECT MARKETING (ART. 21 GDPR)
IF DATA PROCESSING IS BASED ON ART. 6 PARA. 1 LIT. E OR F GDPR, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME, ON GROUNDS RELATING TO YOUR PARTICULAR SITUATION, TO THE PROCESSING OF YOUR PERSONAL DATA; THIS ALSO APPLIES TO PROFILING BASED ON THESE PROVISIONS. THE RESPECTIVE LEGAL BASIS ON WHICH PROCESSING IS BASED CAN BE FOUND IN THIS PRIVACY POLICY. IF YOU OBJECT, WE WILL NO LONGER PROCESS YOUR AFFECTED PERSONAL DATA UNLESS WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING THAT OVERRIDE YOUR INTERESTS, RIGHTS, AND FREEDOMS OR THE PROCESSING SERVES TO ESTABLISH, EXERCISE, OR DEFEND LEGAL CLAIMS (OBJECTION PURSUANT TO ART. 21 PARA. 1 GDPR).
IF YOUR PERSONAL DATA IS PROCESSED FOR DIRECT MARKETING PURPOSES, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF PERSONAL DATA CONCERNING YOU FOR SUCH MARKETING; THIS ALSO APPLIES TO PROFILING TO THE EXTENT THAT IT IS RELATED TO SUCH DIRECT MARKETING. IF YOU OBJECT, YOUR PERSONAL DATA WILL NO LONGER BE USED FOR DIRECT MARKETING PURPOSES (OBJECTION PURSUANT TO ART. 21 PARA. 2 GDPR).
Complaint to the Supervisory Authority
In the event of violations of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, place of work, or the place of the alleged infringement. The right to lodge a complaint exists without prejudice to any other administrative or judicial remedies.
Right to Data Portability
You have the right to receive data that we process automatically based on your consent or in fulfillment of a contract, in a commonly used, machine-readable format, either for yourself or for transfer to a third party. If you request the direct transfer of data to another controller, this will only be done to the extent that it is technically feasible.
SSL or TLS Encryption
For security reasons and to protect the transmission of confidential content—such as orders or inquiries you send to us as the website operator—this site uses SSL or TLS encryption. You can recognize an encrypted connection by the change in the browser's address line from “http://” to “https://” and by the lock icon in your browser's address bar.
When SSL or TLS encryption is enabled, the data you transmit to us cannot be read by third parties.
Right of Access, Erasure, and Rectification
Within the framework of applicable legal provisions, you have the right at any time to receive, free of charge, information about your stored personal data, their origin and recipients, the purpose of data processing, and, if applicable, a right to rectification or erasure of such data. For this purpose, as well as for any further questions relating to personal data, you can contact us at any time at the address provided in the legal notice (Impressum).
Right to Restriction of Processing
You have the right to request the restriction of the processing of your personal data. You may contact us at any time at the address indicated in the legal notice. The right to restriction applies in the following cases:
- If you contest the accuracy of your personal data stored with us, we usually need time to verify this. For the duration of the verification process, you have the right to request the restriction of the processing of your personal data.
- If the processing of your personal data was or is unlawful, you may request the restriction of data processing instead of deletion.
- If we no longer need your personal data but you require them for the establishment, exercise, or defense of legal claims, you have the right to request the restriction of the processing instead of deletion.
- If you have objected pursuant to Article 21(1) GDPR, a balancing of your interests and ours must be carried out. As long as it is not yet determined whose interests prevail, you have the right to request the restriction of the processing of your personal data.
If you have restricted the processing of your personal data, such data—apart from being stored—may only be processed with your consent or for the establishment, exercise, or defense of legal claims, for the protection of the rights of another natural or legal person, or for reasons of important public interest of the European Union or a Member State.
Objection to Promotional Emails
We hereby object to the use of contact data published as part of the legal notice obligations for the transmission of unsolicited advertising and informational materials. The operators of this website expressly reserve the right to take legal action in the event of the unsolicited sending of promotional information, such as spam emails.
4. Data Collection on This Website
Cookies
Our website uses so-called “cookies.” Cookies are small text files that do not cause any damage to your device. They are either stored temporarily for the duration of a session (session cookies) or permanently (persistent cookies) on your device. Session cookies are automatically deleted at the end of your visit. Persistent cookies remain stored on your device until you delete them yourself or your web browser automatically deletes them.
In some cases, cookies from third-party companies may also be stored on your device when you visit our website (third-party cookies). These cookies enable us or you to use certain services provided by the third party (e.g., cookies for processing payment services).
Cookies serve various functions. Many cookies are technically necessary, as certain website functionalities would not work without them (e.g., the shopping cart function or the display of videos). Other cookies are used to analyze user behavior or display advertising.
Cookies that are required to carry out the electronic communication process (necessary cookies), to provide certain functions you have requested (functional cookies, such as for the shopping cart), or to optimize the website (e.g., cookies for measuring the web audience), are stored based on Art. 6(1)(f) of the GDPR, unless another legal basis is specified. The website operator has a legitimate interest in storing cookies to ensure the technically error-free and optimized provision of its services. If consent has been requested for the storage of cookies, the respective cookies are stored exclusively on the basis of this consent (Art. 6(1)(a) GDPR); this consent may be withdrawn at any time.
You can configure your browser to notify you about the use of cookies and to allow cookies only in individual cases, to accept cookies for certain cases or in general, and to activate the automatic deletion of cookies when closing the browser. Disabling cookies may limit the functionality of this website.
Where cookies are used by third-party companies or for analytical purposes, you will be informed separately within this privacy notice and, if necessary, your consent will be requested.
Cookie Consent with Cookiebot
Our website uses a web service provided by Cybot A/S, Havnegade 39, 1058 Copenhagen, Denmark (hereinafter referred to as: cookiebot.com).
We use this service to ensure the full functionality of our website.
In this context, your browser may transmit personal data to cookiebot.com.
The legal basis for the data processing is Article 6(1)(f) of the GDPR.
Our legitimate interest lies in the proper and error-free operation of the website.
The data will be deleted as soon as the purpose of their collection has been fulfilled.
If the user consents to the use of cookies, the following data will be automatically logged by Cybot:
- The anonymized IP address of the user;
- The date and time of consent;
- The user agent of the end user's browser;
- The URL from which the consent was given;
- A random, encrypted, and anonymous key;
- The user's consent status (cookie consent), serving as proof of consent.
The encrypted key and the consent status are stored on the user's device in a cookie in order to restore the respective consent status during future page requests. This cookie automatically expires after 12 months.
Further information regarding the handling of transmitted data can be found in the privacy policy of cookiebot.com: https://www.cookiebot.com/en/privacy-policy/
You can prevent the collection and processing of your data by cookiebot.com by disabling the execution of script code in your browser or by installing a script blocker in your browser.
Privacy Notice – Contact Form
When you send us inquiries via our contact form, the information you provide, including the contact details you enter, will be stored by us for the purpose of processing your inquiry and in case of follow-up questions. We do not disclose this data without your consent.
The processing of this data is based on Article 6(1)(b) of the GDPR if your request is related to the performance of a contract or is necessary to take steps prior to entering into a contract. In all other cases, the processing is based on our legitimate interest in the effective handling of inquiries addressed to us (Article 6(1)(f) GDPR) or on your consent (Article 6(1)(a) GDPR) if this has been requested.
The data you enter in the contact form will be retained by us until you request its deletion, revoke your consent to its storage, or the purpose for storing the data no longer applies (e.g., once your inquiry has been fully processed). Mandatory statutory provisions – in particular retention periods – remain unaffected.
Privacy Notice – Inquiries by Email, Telephone or Fax
If you contact us by email, telephone, or fax, your inquiry including all personal data resulting from it (such as name and request details) will be stored and processed by us for the purpose of handling your request. We do not disclose this data without your consent.
The processing of this data is based on Article 6(1)(b) of the GDPR if your request is related to the performance of a contract or is necessary to take steps prior to entering into a contract. In all other cases, the processing is based on our legitimate interest in the effective handling of inquiries addressed to us (Article 6(1)(f) GDPR) or on your consent (Article 6(1)(a) GDPR) if this has been requested.
The data you transmit to us as part of your inquiry will remain with us until you request deletion, revoke your consent to storage, or the purpose for storing the data no longer applies (e.g., after your request has been fully processed). Mandatory legal requirements – in particular statutory retention periods – remain unaffected.
5. Social Media
Facebook Plugins (Like & Share Button)
This website integrates plugins from the social network Facebook. The provider of this service is Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland. According to Facebook, the collected data is also transferred to the USA and other third countries.
You can recognize Facebook plugins by the Facebook logo or the “Like” button (“Gefällt mir”) displayed on this website. An overview of Facebook plugins can be found here: https://developers.facebook.com/docs/plugins/?locale=de_DE.
When you visit this website, a direct connection is established between your browser and the Facebook server via the plugin. Through this connection, Facebook receives the information that you have visited this website with your IP address. If you click the Facebook “Like” button while logged into your Facebook account, you can link the content of this website to your Facebook profile. This enables Facebook to associate your visit to this website with your user account. We would like to point out that as the provider of this website, we have no knowledge of the content of the transmitted data or its use by Facebook. For more information, please refer to Facebook’s privacy policy at: https://de-de.facebook.com/privacy/explanation.
If you do not want Facebook to be able to associate your visit to this website with your Facebook user account, please log out of your Facebook account.
The use of Facebook plugins is based on Article 6(1)(f) of the GDPR. The website operator has a legitimate interest in achieving the widest possible visibility in social media. Where consent has been obtained, processing is carried out exclusively on the basis of Article 6(1)(a) of the GDPR; consent may be revoked at any time.
Instagram Plugin
This website incorporates functions of the Instagram service. These functions are provided by Instagram Inc., 1601 Willow Road, Menlo Park, CA 94025, USA.
If you are logged into your Instagram account, clicking the Instagram button allows you to link content from this website to your Instagram profile. As a result, Instagram may associate your visit to this website with your user account. We would like to point out that, as the provider of this website, we have no knowledge of the content of the data transmitted or how it is used by Instagram.
The storage and analysis of data are carried out on the basis of Art. 6(1)(f) of the GDPR. The website operator has a legitimate interest in achieving the broadest possible visibility in social media. If consent has been requested, the processing is based solely on Art. 6(1)(a) of the GDPR; consent may be withdrawn at any time.
Further information on this can be found in Instagram's privacy policy: https://instagram.com/about/legal/privacy/.
6. Analytics Tools and Advertising
Google Analytics
This website uses functions of the web analytics service Google Analytics. The provider is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.
Google Analytics enables the website operator to analyze the behavior of website visitors. The operator may receive various usage data, such as page views, session duration, operating systems used, and the origin of the user. These data may be compiled by Google into a profile associated with the respective user or their device.
Google Analytics uses technologies that facilitate user recognition for the purpose of behavioral analysis (e.g., cookies or device fingerprinting). The information collected by Google regarding your use of this website is typically transferred to and stored on a Google server in the United States.
The use of this analytical tool is based on Art. 6(1)(f) GDPR. The website operator has a legitimate interest in analyzing user behavior in order to optimize both their website and advertising. If user consent was obtained (e.g., consent to the storage of cookies), the data processing is exclusively based on Art. 6(1)(a) GDPR; such consent can be revoked at any time.
IP Anonymization
We have activated the IP anonymization function on this website. This means that your IP address is truncated by Google within member states of the European Union or in other signatory states of the Agreement on the European Economic Area before transmission to the USA. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and truncated there. Google uses this information on behalf of the website operator to evaluate your use of the website, compile reports on website activity, and provide other services related to website and internet usage. The IP address transmitted by your browser within the context of Google Analytics will not be merged with other Google data.
Browser Plugin
You can prevent the collection and processing of your data by Google by downloading and installing the browser plugin available at the following link: https://tools.google.com/dlpage/gaoptout?hl=en
Further information on how Google Analytics handles user data can be found in Google’s privacy policy: https://support.google.com/analytics/answer/6004245?hl=en
Data Processing Agreement
We have entered into a data processing agreement with Google and fully comply with the strict requirements of German data protection authorities when using Google Analytics.
Demographic Features in Google Analytics
This website uses the “demographics” feature of Google Analytics. It allows the creation of reports that include information on the age, gender, and interests of site visitors. These data are derived from interest-based advertising by Google and from third-party visitor data. This data cannot be attributed to a specific individual. You can disable this feature at any time via the ad settings in your Google account or generally prohibit the collection of your data by Google Analytics as described under “Objection to Data Collection.”
Retention Period
Data stored by Google at the user and event level that is linked to cookies, user identifiers (e.g., User ID), or advertising IDs (e.g., DoubleClick cookies, Android Advertising ID) is anonymized or deleted after 26 months. For details, please visit: https://support.google.com/analytics/answer/7667196?hl=en
Google Ads
This website uses Google Ads, an online advertising program provided by Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.
Google Ads enables us to display advertisements in the Google search engine or on third-party websites when users enter specific search terms (keyword targeting). Targeted advertisements can also be displayed based on user data held by Google (e.g., location data and interests) (audience targeting). As website operators, we can evaluate this data quantitatively, such as by analyzing which search terms triggered the display of our ads and how many ads led to corresponding clicks.
The use of Google Ads is based on Art. 6(1)(f) GDPR. The website operator has a legitimate interest in the most effective possible marketing of its services and products.
Google Remarketing
This website uses the features of Google Analytics Remarketing. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Google Remarketing analyzes your user behavior on our website (e.g., clicks on specific products) to classify you into specific advertising target groups and subsequently display tailored advertising messages to you when you visit other online offerings (remarketing or retargeting).
In addition, the advertising target groups created with Google Remarketing can be linked to Google’s cross-device features. This allows interest-based, personalized advertising messages that were adapted based on your prior usage and browsing behavior on one device (e.g., smartphone) to also be displayed on another of your devices (e.g., tablet or PC).
If you have a Google account, you can object to personalized advertising at the following link: https://www.google.com/settings/ads/onweb/
The use of Google Remarketing is based on Art. 6(1)(f) GDPR. The website operator has a legitimate interest in the most effective marketing of its products. If corresponding consent was obtained, processing is carried out exclusively on the basis of Art. 6(1)(a) GDPR; consent may be revoked at any time.
Further information and the data protection provisions can be found in Google’s privacy policy: https://policies.google.com/technologies/ads?hl=en
Google Conversion Tracking
This website uses Google Conversion Tracking. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
With the help of Google Conversion Tracking, we and Google can identify whether the user has performed specific actions. For instance, we can analyze which buttons on our website are clicked and how often, and which products are viewed or purchased frequently. This information helps us create conversion statistics. We learn the total number of users who clicked on our ads and what actions they performed. However, we do not receive information that personally identifies users. Google uses cookies or comparable recognition technologies for identification.
The use of Google Conversion Tracking is based on Art. 6(1)(f) GDPR. The website operator has a legitimate interest in analyzing user behavior to optimize both the website and advertising. If user consent was obtained (e.g., for cookie storage), processing is based solely on Art. 6(1)(a) GDPR; consent may be revoked at any time.
Further information on Google Conversion Tracking can be found in Google’s privacy policy: https://policies.google.com/privacy?hl=en
Google Tag Manager
This website uses Google Tag Manager, a tag management system that operates without cookies and does not collect personal data.
This tool enables the integration and management of “website tags” (i.e., tags embedded in HTML elements) via an interface. Using Google Tag Manager allows us to automatically record which button, link, or personalized image you have actively clicked and then identify which content on our website is of particular interest to you.
The tool may trigger other tags that may themselves collect data. Google Tag Manager does not access these data. If deactivation is made at the domain or cookie level, it will remain in effect for all tracking tags implemented with Google Tag Manager.
These processing activities occur solely on the basis of your explicit consent in accordance with Art. 6(1)(a) GDPR.
7. Newsletter
Newsletter Data
If you wish to subscribe to the newsletter offered on our website, we require your email address as well as information that allows us to verify that you are the owner of the provided email address and that you consent to receiving the newsletter. No further data is collected unless provided voluntarily. This data is used exclusively for sending the requested information and will not be disclosed to third parties.
The processing of the data entered in the newsletter subscription form is based solely on your consent (Art. 6(1)(a) GDPR). You may withdraw your consent to the storage of your data, email address, and its use for sending the newsletter at any time, for example via the “unsubscribe” link included in each newsletter. The legality of any data processing already carried out remains unaffected by the withdrawal.
The data you provide for the purpose of receiving the newsletter will be stored by us or the newsletter service provider until you unsubscribe from the newsletter and will be deleted from the newsletter distribution list after you unsubscribe. Any data stored for other purposes remains unaffected.
After unsubscribing from the newsletter distribution list, your email address may be stored in a blacklist either by us or by the newsletter service provider to prevent future mailings. The data stored in the blacklist will be used solely for this purpose and will not be combined with other data. This serves both your interest and our interest in complying with legal requirements for the sending of newsletters (legitimate interest within the meaning of Art. 6(1)(f) GDPR). The storage in the blacklist is indefinite. You may object to this storage if your interests outweigh our legitimate interest.
Use of Sendinblue
This website uses Sendinblue for the dispatch of newsletters. The provider is Sendinblue GmbH, Köpenicker Straße 126, 10179 Berlin, Germany.
Sendinblue is a service that helps organize and analyze newsletter distribution. The data you enter for the purpose of subscribing to the newsletter is stored on Sendinblue’s servers in Germany.
If you do not wish for your data to be analyzed by Sendinblue, you must unsubscribe from the newsletter. We provide a link for this purpose in every newsletter message. You can also unsubscribe directly on the website.
Data Analysis by Sendinblue
With the help of Sendinblue, we are able to analyze our newsletter campaigns. For example, we can see whether a newsletter message was opened and which links were clicked, if any. This allows us to determine, among other things, which links were clicked most often.
We can also identify whether certain predefined actions were taken after opening/clicking (conversion rate). For example, we can determine whether you made a purchase after clicking the newsletter.
Sendinblue also allows us to segment newsletter recipients by various categories (e.g., age, gender, place of residence). This enables us to better tailor the newsletter to specific target groups.
Detailed information on the functionalities of Sendinblue can be found at: https://de.sendinblue.com/newsletter-software/
Legal Basis
Data processing is based on your consent (Art. 6(1)(a) GDPR). You may withdraw this consent at any time. The legality of data processing that has already occurred remains unaffected by the withdrawal.
Storage Period
The data you provide for the purpose of receiving the newsletter will be stored until you unsubscribe and will be deleted from the distribution list thereafter. Data stored for other purposes remains unaffected.
After unsubscribing, your email address may be stored in a blacklist to prevent future mailings. The data in the blacklist will only be used for this purpose and will not be merged with other data. This is in both your interest and ours in complying with legal requirements for newsletter distribution (legitimate interest pursuant to Art. 6(1)(f) GDPR). The storage in the blacklist is indefinite. You may object to this storage if your interests outweigh our legitimate interest.
For more details, please refer to Sendinblue’s privacy policy: https://de.sendinblue.com/datenschutz-uebersicht/
Data Processing Agreement
We have entered into a data processing agreement with Sendinblue in which we require Sendinblue to protect the data of our customers and not to disclose it to third parties.
8. Plugins and Tools
YouTube
This website integrates videos from the YouTube platform. The provider of this service is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.
When you visit one of our web pages featuring a YouTube video, a connection is established to YouTube's servers. In doing so, the YouTube server is informed about which of our pages you have visited.
Additionally, YouTube may store cookies on your device or use comparable recognition technologies (e.g., device fingerprinting). In this way, YouTube may obtain information about visitors to our website. Such data is used, among other purposes, to compile video statistics, improve user experience, and prevent fraudulent activities.
If you are logged into your YouTube account, YouTube can associate your browsing behavior directly with your personal profile. You can prevent this by logging out of your YouTube account.
The use of YouTube serves the interest of providing an attractive presentation of our online offerings. This constitutes a legitimate interest pursuant to Art. 6(1)(f) GDPR. If the corresponding consent has been requested, the processing is carried out exclusively on the basis of Art. 6(1)(a) GDPR; consent can be revoked at any time.
Further information on the handling of user data can be found in YouTube’s privacy policy at: https://policies.google.com/privacy?hl=en.
Google reCAPTCHA
We use "Google reCAPTCHA" (hereinafter "reCAPTCHA") on this website. The provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.
The purpose of reCAPTCHA is to determine whether data entered on this website (e.g., via a contact form) is submitted by a human or by an automated program. For this purpose, reCAPTCHA analyzes the behavior of website visitors based on various characteristics. This analysis begins automatically as soon as the website visitor enters the website. The data evaluated by the analysis includes, for example, the IP address, time spent on the site, and user interactions such as mouse movements. The data collected during the analysis is forwarded to Google.
These reCAPTCHA analyses run entirely in the background. Website visitors are not advised that such analysis is taking place.
The data is processed on the basis of Art. 6(1)(f) GDPR. The website operator has a legitimate interest in protecting its online offerings from abusive automated spying and from spam. If consent has been obtained, processing is based exclusively on Art. 6(1)(a) GDPR; the consent can be revoked at any time.
Further information regarding Google reCAPTCHA can be found in Google's privacy policy and terms of use at:
https://policies.google.com/privacy?hl=en and
https://policies.google.com/terms?hl=en.
9. E-Commerce and Payment Providers
Processing of Data (Customer and Contract Data)
We collect, process, and use personal data only to the extent necessary for the establishment, content-related design, or modification of the legal relationship (inventory data). This is done based on Art. 6(1)(b) GDPR, which permits data processing for the performance of a contract or pre-contractual measures.
We collect, process, and use personal data concerning the use of this website (usage data) only to the extent necessary to enable the user to make use of the service or to bill the user.
The collected customer data will be deleted after completion of the order or termination of the business relationship. Statutory retention periods remain unaffected.
10. Audio and Video Conferences
Data Processing
For communication with our customers, we use various online conferencing tools. The specific tools we use are listed below. If you communicate with us via video or audio conference over the internet, your personal data will be collected and processed by both us and the respective provider of the conferencing tool.
These tools collect all data that you provide for their use (such as your email address and/or telephone number). In addition, the tools process information such as the duration of the conference, start and end times of participation, number of participants, and other "contextual information" related to the communication process (metadata).
Furthermore, the tool provider processes all technical data required for the handling of online communications. This includes, in particular, IP addresses, MAC addresses, device IDs, device type, operating system type and version, client version, camera type, microphone or speaker, and the type of connection used.
If content is exchanged, uploaded, or otherwise made available within the tool, this content is also stored on the servers of the respective tool provider. Such content may include, in particular, cloud recordings, chat/instant messages, voicemails, uploaded photos and videos, files, whiteboards, and other information shared while using the service.
Please note that we do not have full control over the data processing activities of the tools used. Our influence is primarily governed by the corporate policies of the respective providers. For more detailed information on data processing by the conferencing tools, please refer to the privacy statements of the providers listed below.
Purpose and Legal Basis
We use conferencing tools to communicate with prospective or existing contractual partners or to offer specific services to our customers (Art. 6(1)(1)(b) GDPR). Additionally, the use of these tools serves the general facilitation and acceleration of communication with us and within our organization (legitimate interest within the meaning of Art. 6(1)(f) GDPR). Where consent has been requested, the relevant tools are used on the basis of such consent; this consent may be revoked at any time with effect for the future.
Retention Period
Data directly collected by us via video and conferencing tools will be deleted from our systems as soon as you request deletion, withdraw your consent to storage, or the purpose for data storage no longer applies. Stored cookies remain on your device until you delete them. Mandatory statutory retention periods remain unaffected.
We have no influence over the retention period of your data as stored by the operators of the conferencing tools for their own purposes. For details on this, please consult the privacy policies of the respective conferencing tool providers.
Conferencing Tools Used
Zoom
We use Zoom. The provider of this service is Zoom Communications Inc., 55 Almaden Boulevard, 6th Floor, San Jose, CA 95113, USA. For details on data processing, please refer to Zoom’s privacy policy:
https://zoom.us/de-de/privacy.html
Data Processing Agreement
We have entered into a data processing agreement with the provider of Zoom and fully implement the strict requirements of the German data protection authorities when using Zoom.
Microsoft Teams
We use Microsoft Teams. The provider is Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA. For details on data processing, please refer to Microsoft Teams’ privacy policy:
https://privacy.microsoft.com/de-de/privacystatement
Data Processing Agreement
We have entered into a data processing agreement with the provider of Microsoft Teams and fully implement the strict requirements of the German data protection authorities when using Microsoft Teams.
11. Own Services
Handling of Applicant Data
We offer you the opportunity to apply with us (e.g. by email, postal mail, or via an online application form). Below, we inform you about the scope, purpose, and use of your personal data collected during the application process. We assure you that the collection, processing, and use of your data complies with applicable data protection legislation and all other legal requirements, and that your data will be treated with the strictest confidentiality.
Scope and Purpose of Data Collection
When you submit an application to us, we process the personal data associated with it (e.g. contact and communication details, application documents, interview notes, etc.), insofar as this is necessary for making a decision regarding the establishment of an employment relationship. The legal basis for this is Section 26 of the new German Federal Data Protection Act (BDSG-neu) (initiation of an employment relationship), Article 6(1)(b) of the General Data Protection Regulation (GDPR) (general contract initiation), and—if you have given your consent—Article 6(1)(a) GDPR. Consent may be revoked at any time. Within our company, your personal data will only be shared with individuals who are involved in processing your application.
If your application is successful, the data you have submitted will be stored in our data processing systems for the purpose of implementing the employment relationship, based on Section 26 BDSG-neu and Article 6(1)(b) GDPR.
Data Retention Period
If we are unable to offer you a position, if you decline a job offer, or if you withdraw your application, we reserve the right to retain the data you have submitted for up to six months after the conclusion of the application process (rejection or withdrawal of the application) based on our legitimate interests in accordance with Article 6(1)(f) GDPR. The data will then be deleted, and any physical application documents will be destroyed. Retention serves in particular as evidence in the event of a legal dispute. If it becomes apparent that the data will be required after the six-month period (e.g. due to a potential or pending legal dispute), the data will only be deleted once the purpose for continued storage no longer applies.
Longer retention may also occur if you have given your explicit consent (Article 6(1)(a) GDPR) or if statutory retention obligations prevent deletion.
12. Our Social Media Presence
Data Processing by Social Networks
We operate publicly accessible profiles on various social media platforms. The specific social networks we use are listed below.
Social networks such as Facebook, Twitter, and others typically analyze your user behavior comprehensively when you visit their websites or websites with integrated social media content (e.g. like buttons or advertising banners). When you visit our social media profiles, numerous data processing operations relevant to data protection are triggered. Specifically:
If you are logged into your social media account and visit our profile, the operator of the social media platform can associate this visit with your user account. Your personal data may also be collected even if you are not logged in or do not have an account with the respective platform. This data collection may occur through cookies stored on your device or by capturing your IP address.
The data collected in this way may be used by the social media platform operators to create user profiles in which preferences and interests are stored. These profiles can be used to serve personalized advertisements within and outside the respective social media platforms. If you have an account with the respective social network, interest-based advertising can be displayed on all devices on which you are or were logged in.
Please note that we cannot fully track all data processing activities on the social media platforms. Depending on the provider, additional processing operations may therefore be carried out by the platform operators. For further details, please refer to the terms of use and privacy policies of the respective social media platforms.
Legal Basis
Our presence on social media is intended to ensure the broadest possible visibility on the Internet, which constitutes a legitimate interest as defined by Art. 6(1)(f) GDPR. The analysis processes initiated by the social networks themselves may be based on different legal grounds, which must be stated by the respective social network operators (e.g. consent as defined by Art. 6(1)(a) GDPR).
Joint Responsibility and Exercising of Rights
If you visit one of our social media profiles (e.g. on Facebook), we are jointly responsible with the operator of the social media platform for the data processing operations triggered by your visit. You may exercise your rights (e.g. access, rectification, erasure, restriction of processing, data portability, and complaint) both against us and the respective platform operator (e.g. Facebook).
Please note that despite the joint responsibility with the social media platform operators, our influence on the data processing operations is limited and largely depends on the policies of the respective providers.
Storage Period
Data directly collected by us via our social media profiles is deleted from our systems as soon as the purpose for its storage no longer applies, you request its deletion, withdraw your consent to storage, or the purpose for data storage ceases to exist. Cookies remain on your device until you delete them. Mandatory legal provisions—particularly retention periods—remain unaffected.
We have no control over the storage duration of your data that is stored by the social network operators for their own purposes. For details, please consult the privacy policies of the respective providers (see below).
13. Social Networks in Detail
Facebook
We operate a profile on Facebook. The provider of this service is Facebook Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland. According to Facebook, the data collected may also be transferred to the USA and other third countries.
We have entered into a Joint Controllership Agreement (Controller Addendum) with Facebook. This agreement stipulates which data processing operations we or Facebook are responsible for when you visit our Facebook Page. The agreement can be accessed at the following link:
https://www.facebook.com/legal/terms/page_controller_addendum.
You can manage your advertising preferences independently within your user account by clicking the following link and logging in:
https://www.facebook.com/settings?tab=ads.
For further details, please refer to Facebook’s Privacy Policy:
https://www.facebook.com/about/privacy/
Twitter
We use the short message service Twitter. The provider is Twitter Inc., 1355 Market Street, Suite 900, San Francisco, CA 94103, USA.
You can independently adjust your Twitter privacy settings in your user account by clicking the following link and logging in:
https://twitter.com/personalization
Further information is available in Twitter’s Privacy Policy:
https://twitter.com/privacy
Instagram
We maintain a profile on Instagram. The provider is Instagram Inc., 1601 Willow Road, Menlo Park, CA 94025, USA.
For information on how your personal data is handled, please refer to Instagram’s Privacy Policy:
https://help.instagram.com/519522125107875
XING
We operate a profile on XING. The provider is New Work SE, Dammtorstraße 30, 20354 Hamburg, Germany.
For details on how your personal data is processed, please refer to XING’s Privacy Policy:
https://privacy.xing.com/en/privacy-policy
LinkedIn
We maintain a profile on LinkedIn. The provider is LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland. LinkedIn uses advertising cookies.
If you wish to deactivate LinkedIn advertising cookies, please use the following link:
https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out
For more information on how your personal data is handled, please refer to LinkedIn’s Privacy Policy:
https://www.linkedin.com/legal/privacy-policy
YouTube
We operate a profile on YouTube. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
For information on how your personal data is processed, please refer to YouTube’s Privacy Policy: https://policies.google.com/privacy