- Personal Data: means any information relating to a natural person who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, or an online identifier.
- Processing: means any operation which is performed on personal data, such as collection, recording, organisation, structuring, storage, adaptation or any kind of disclosure or other use.
II. Processing operations
- Ensuring the security and stability of the website
If you visit this website, we will collect from you and log the following personal data:
- IP address;
- type of device, device name, your device-ID;
- date, time and content of your request;
- your browser version and screen resolution;
- information about your operating system, including your language settings.
Such website logs are used solely for the purpose of ensuring the security of our website and will be stored for no longer than 14 days. The processing is based on our legitimate interests to protect the integrity and availability of our website (Art. 6 para. 1(f) GDPR).
- Responding to your requests
If you are using a contact form provided on this website or contact us through other means, we may collect and process the following personal data:
- email address;
- telephone number;
- job title;
- content of your request.
We use your personal data to the extent necessary for the initiation of a contract upon your request, to answer your custom inquiry and to provide you with all related information. The processing is based on our legitimate interest to establish a business relation with your employer (Article 6 para. 1(f) GDPR).
- Provision of our services
If your employer enters into a service contract with us, we may collect the following information from you:
- email address;
- telephone number;
- job title;
- communications and copies of documents which include personal information, such as signatures on contracts.
We use your personal data to the extent necessary for the fulfillment of our contract with your employer, such as through individual consulting services, the provision of access to an online information database (“DPO Cockpit”) and the provision of updates on data privacy laws via email. The processing is based on our legitimate interest to deliver our services to your employer in line with the contractual arrangements (Article 6 para. 1(f) GDPR), and to comply with statutory requirements, such as under Article 39 GDPR (Article 6 para. 1(c) GDPR).
- Email marketing
If we have received your email address in connection with the delivery of a service, we may send direct marketing content to your e-mail-address about our own similar products and services if you have not refused such use. You can object to such sending of direct marketing content at any time. A link to unsubscribe will be provided in each email we send to you.
- Automated decision-making
We do not use your personal data for automated decision-making which produces legal effects concerning you or similarly significantly affects you.
- Information sharing
In the event that we undergo reorganisation or are sold to a third party, any personal data we hold about you may be transferred to that reorganised entity or third party in compliance with applicable law. We may also disclose your personal data if legally entitled or required to do so (for example if required by law or by a court order).
We may commission third party service providers (data processors) in compliance with applicable law to carry out certain data processing on our behalf, such as services to support us with tax declarations and documentation, or with the delivery of email and invoices.
We have reasonable state of the art security measures in place to protect against the loss, misuse and alteration of personal data under our control. Whilst we cannot ensure or guarantee that loss, misuse or alteration of information will never occur, we use reasonable efforts to prevent it. You should bear in mind that submission of information over the internet is never entirely secure. We cannot guarantee the security of information you submit via our website whilst it is in transit over the internet and any such submission is at your own risk.
IV. Data retention
We strive to keep our processing activities with respect to your personal data as limited as possible. In the absence of specific retention periods set out in this policy, your personal data will be retained only for as long as we need it to fulfil the purpose for which we have collected it. Business- and tax-related communications may be subject to statutory retention periods of six to ten years.
V. Your Rights
Under the legislation applicable to you, you may be entitled to exercise some or all of the following rights:
- require (i) information whether your personal data is retained and (ii) access to and/or duplicates of your personal data retained, including the purposes of the processing, the categories of personal data concerned, and the data recipients as well as potential retention periods;
- request rectification, removal or restriction of your personal data, e.g. because (i) it is incomplete or inaccurate, (ii) it is no longer needed for the purposes for which it was collected, or (iii) the consent on which the processing was based has been withdrawn;
- refuse to provide and – without impact to data processing activities that have taken place before such withdrawal – withdraw your consent to processing of your personal data at any time;
- not to be subject to any automated decision making, including profiling (automatic decisions based on data processing by automatic means, for the purpose of assessing several personal aspects) which produce legal effects on you or affects you with similar significance;
- require (i) to receive the personal data concerning you, which you have provided to us, in a structured, commonly used and machine-readable format and (ii) to transmit those data to another controller without hindrance from our side; where technically feasible you shall have the right to have the personal data transmitted directly from us to another controller;
- take legal actions in relation to any potential breach of your rights regarding the processing of your Personal data, as well as to lodge complaints before the competent data protection regulators;
- object at any time:
- if we use your personal data for the purpose of direct marketing; or
- on grounds relating to your particular situation
that your personal data shall be subject to a processing.
VI. Contacting us
Please submit any questions, concerns or comments you have about this Policy or any requests concerning your personal data by email to us. You can contact us via firstname.lastname@example.org. The Information you provide when contacting us (name, address, telephone number) will be processed to handle your request and will be erased when your request was completed. Alternatively, we will restrict the processing of the respective Information in accordance with statutory retention requirements.
VII. Amendments to this policy
We reserve the right to change this Policy from time to time by updating our website respectively. Please visit the website regularly and check our respectively current Policy. This Policy was last updated on 28 July 2020.