Data Protection and Privacy Statement

Dussmann Group

Preamble

This text explains what types of personal data concerning you (also referred to herein as “data”) Dussmann processes for which purposes and in what scope. This Data Protection and Privacy Statement applies to all processing of personal data by Dussmann, both within the context of the use of the Dussmann online career portal and on Dussmann websites (collectively referred to as “online services”) or in the case of applications received by e-mail or submitted on site.

It is important to note that Dussmann is not merely a single company. It is a group of companies consisting of Dussmann Stiftung & Co. KGaA and its affiliates. A list of these affiliates can be viewed here. Not every one of these affiliates does in fact process your data. For ease of reference, the “Controller” section notes which company is responsible for processing your data. This means that where the text below refers to “us” or “we”, this means the responsible company of the Dussmann Group that is mentioned in the “Controller” section.

Please check back regularly to familiarize yourself with the content of our Data Protection and Privacy Statement. We adjust the text promptly as required by changes in the data processing we perform. We will let you know if and when these changes require any participatory action on your part (such as consent) or another form of individual notification is necessary.

Where we state the addresses and contact information of companies and organizations in this Data Protection and Privacy Statement, please note that these addresses may change over time and should be verified before you contact us.

 

Controller

Dussmann Stiftung & Co. KGaA
Friedrichstrasse 90
10117 Berlin
Germany

e-mail address: hotline @remove-this.dussmanngroup.com

Phone: +49 30 20 250

 

Data protection officer contact

Dussmann Stiftung & Co. KGaA
Data Protection Officer
Friedrichstrasse 90
10117 Berlin
Germany
+49 30 20250
datenschutz @remove-this.dussmanngroup.com

 

Overview of processing

The overview below summarizes the types of data we process and the purposes of processing thereof and indicates the data subjects.

Types of data processed

  • Inventory data
  • Payment data
  • Location data
  • Contact information
  • Content-related data
  • Usage data
  • Metadata, communication data, process data
  • Images and/or video recordings
  • Audio recordings
  • Log data

Special categories of data

  • Data concerning health
  • Religious or philosophical beliefs
  • Trade union membership
  • Sex life or sexual orientation

Categories of data subjects

  • Communication partners
  • Users
  • Persons depicted

Purposes of processing

  • Communication
  • Security measures
  • Reach measurement
  • Office and organizational procedures
  • Organizational and administrative procedures
  • Feedback
  • Provision of our online services and user friendliness
  • Performance of application process
  • Information technology infrastructure

 

Relevant legal bases

Relevant legal bases pursuant to the GDPR: This section provides an overview of the legal bases under the GDPR on which we process personal data. Please note that in addition to the provisions of the GDPR, national data protection and privacy specifications may apply in your or our country of residence or domicile. Should more-specific legal bases be relevant in the individual case, we will notify you of these in the Data Protection and Privacy Statement.

  • Consent (point (a) of Article 6(1) GDPR) – The data subject has given consent to the processing of his or her personal data for one or more specific purposes.
  • Performance of a contract or inquiries prior to entering into a contract (point (b) of Article 6(1) GDPR) – Processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.
  • Legal obligation (point (c) of Article 6(1) GDPR) – Processing is necessary for compliance with a legal obligation to which the controller is subject.
  • Legitimate interests (point (f) of Article 6(1) GDPR) – Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data.
  • Explicit consent (point (a) of Article 9(2) GDPR) – The data subject has given explicit consent to the processing of those personal data of special categories for one or more specified purposes.
  • Exercising of rights (point (b) of Article 9(2) GDPR) – Processing is necessary for the purposes of carrying out the obligations and exercising specific rights of the controller or of the data subject in the field of employment and social security and social protection law.

National data protection regulations in Germany: In addition to the data protection regulations stipulated by the GDPR, there are national regulations governing data protection and privacy in Germany. This particularly includes German Federal Data Protection Act (BDSG). In particular, the BDSG contains special provisions relating to the rights of access to information, of erasure, and to object; the processing of special categories of personal data; processing for other purposes; transfers; and automated decision-making in individual cases, including profiling. Furthermore, state data protection laws at the level of the individual states may also apply.

 

Security measures

In accordance with the legal specifications and taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, we implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk.

These measures include but are not limited to ensuring the confidentiality, integrity, and availability of data by controlling physical and electronic access to the data and the data access concerning them, along with the entry, communication, and separation thereof and ensuring the availability of the data. We have also established procedures that ensure that the rights of data subjects are upheld, data are erased, and there is a response to any risk to the data. Furthermore, we take protecting personal data into account in the early stages of developing and/or selecting hardware, software, and procedures in keeping with the principle of data protection by design and by default.

Safeguarding online connections through TLS/SSL encryption technology (HTTPS): To protect the user data transferred via our online services against unauthorized access, we rely on TLS/SSL encryption technology. Secure Sockets Layer (SSL) and Transport Layer Security (TLS) are the cornerstones of secure data transmission on the Internet. These technologies encrypt the information transferred between the website or app and the user’s browser (or between two servers), which protects the data against unauthorized access. TLS, a further developed and more-secure version of SSL, ensures that all data transmissions meet the very highest standards of security. If a website is safeguarded by an SSL/TLS certificate, “HTTPS” is displayed in the URL. This serves as an indicator for users that their data are being transferred securely and with encryption.

 

Transfers of personal data

Within the scope of our processing of personal data, it is possible that these data will be transferred or disclosed to other bodies, companies, legally independent organizational units, persons, or entities. Recipients of these data may include, for example, service providers commissioned to perform IT tasks or providers of services and content incorporated into a website. In such cases, we observe the legal specifications and, in particular, enter into relevant contracts and/or agreements that serve to protect your data with the recipients of your data.

Data transfers within the corporate group: We may transfer personal data to other companies within our corporate group or grant them access to these data. Where such disclosures take place for administrative purposes, the disclosure of the data is based on our legitimate entrepreneurial and business administration interests or takes place to the extent necessary to fulfill our contract-related obligations or where the data subject has given consent or the disclosure is permitted by law.

 

International data transfers

Data processing in third countries: Where we process data in a third country (i.e., outside the European Union (EU) or European Economic Area (EEA)) or the processing takes place within the scope of our utilization of third-party services or of the disclosure or transfer of data to other persons or entities, bodies, or companies, this takes place solely in compliance with the legal specifications. Where the level of data protection in the third country has been acknowledged by an adequacy decision (Article 45 GDPR), this decision serves as the basis for the data transfer. In all other respects, data transfers take place only if the level of data protection has been safeguarded through other means, particularly standard contractual clauses (point (c) of Article 46(2) GDPR), express consent has been granted, or the transfer is required based on the provisions of a contract or by law (Article 49(1) GDPR). In all other respects, we communicate to you the bases for the third-country transfer in the case of the individual third-country providers; the adequacy decisions take precedence as bases. For information on third-country transfers and existing adequacy decisions, please consult the information provided by the European Commission: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection_en.

Transatlantic EU–U.S. data privacy framework: Within the scope of the Data Privacy Framework (DPF), the European Commission acknowledged the level of data protection provided by certain companies based in the United States as secure under the adequacy decision dated July 10, 2023. The list of certified companies and further information relating to the DPF is available from the U.S. Department of Commerce website at https://www.dataprivacyframework.gov/.

 

Information on data storage and erasure

We erase personal data that we process in accordance with the statutory provisions once the underlying consent has been withdrawn or there are no further legal bases for the processing thereof. This applies to cases in which the original purpose of processing ceases to apply or the data are no longer required. Exceptions to this provision apply if statutory obligations or particular interests require that the data be retained or archived for a longer period.

In particular, data that must be retained for reasons of commercial or tax law or whose storage is necessary in order to pursue legal claims or protect the rights of other natural persons or legal entities must be archived accordingly.

We process data that are no longer retained for the originally intended purpose, but rather based on legal specifications or other reasons, exclusively on the bases that justify the retention thereof.

Should you wish your data to be erased or withdraw consent to data processing, the data will be erased as soon as possible unless there is an obligation to store them.

If we are unable to consider your application, your data will be deleted after 6 months at the latest, unless you allow us to store your data in the applicant pool for a longer period in accordance with point (a) of Article 6(1) GDPR. If you withdraw your application, we will of course delete your data immediately. If your application results in the conclusion of a contract with us, your data will be used for the purpose of the organizational and administrative procedure and in compliance with legal regulations.

Further information on processing operations, procedures, and services:

  • Retention and erasure of data: The following general time limits apply to retention and archiving pursuant to German law:
    • Ten years – retention period for accounts and records, inventories, annual financial statements, management or situation reports, the opening balance sheet as well as the operating instructions and other organizational documents, needed for their comprehension (Sec. 147 (3) in conjunction with (1) Nos. 1 of the German Fiscal Code (AO), Sec. 257 (1) Nos. 1 and (4) of the German Commercial Code (HGB)).
    • Eight years – accounting records and invoices (Sec. 147 (3) in conjunction with (1) Nos. 4 of the German Fiscal Code (AO), Sec. 14b (1) of the German Value-Added Tax Act (UStG), Sec. 257 (1) Nos. 4 and (4) of the German Commercial Code (HGB)).
    • Six years – other business documents: trade or business letters received, reproductions of trade or business letters sent, other documents to the extent that these are of relevance for taxation, such as hourly wage slips, operating expense sheets, calculation documents, pricing materials, but also payroll documents, where these do not already constitute accounting records, and cash register tapes (Sec. 147 (3) in conjunction with (1) Nos. 2, 3, and 5 AO, Sec. 257 (1) Nos. 2 and 3 and (4) HGB).
    • Three years – data that are required in order to take potential warranty claims and claims for damages or similar contractual claims and rights into account and to process inquiries associated therewith, based on past business experience and customary industry practices, are stored for the duration of the regular statutory limitation period of three years (Sec. 195 and 199 BGB).

 

Rights of data subjects

Rights of data subjects under the GDPR: As a data subject, you have various rights under the GDPR, particularly based on Articles 15 through 21 GDPR:

  • Right to object: You have the right to object, on grounds relating to your particular situation, at any time to processing of personal data concerning you which is based on point (e) or (f) of Article 6(1), including profiling based on those provisions. Where personal data concerning you are processed for direct marketing purposes, you have the right to object at any time to the processing of the personal data concerning you for such marketing, which includes profiling to the extent that it is related to such direct marketing.
  • Right to withdraw consent: You have the right to withdraw your consent at any time.
  • Right of access to information: You have the right to obtain confirmation as to whether or not personal data concerning you are being processed, and, where that is the case, access to information about the personal data and to further information and copies of the data in accordance with the legal specifications.
  • Right to rectification: In accordance with the legal specifications, you have the right to have the data concerning you completed if they are incomplete or rectified if they are inaccurate.
  • Right of erasure and restriction of processing: In accordance with the legal specifications, you have the right to have the data concerning you erased without undue delay or, alternatively, to have the processing of these data restricted in accordance with the legal specifications.
  • Right to data portability: You have the right to receive the data concerning you, which you have provided to us, in a structured, commonly used and machine-readable format or to have those data transmitted to another controller in accordance with the legal specifications.
  • Complaint to a supervisory authority: In accordance with the legal specifications and without prejudice to any other administrative or judicial remedy, you moreover have the right to lodge a complaint with a data protection supervisory authority, in particular a supervisory authority in the Member State of your habitual residence or the supervisory authority responsible for your place of work or the place of the alleged infringement, if you consider that the processing of the personal data relating to you infringes the GDPR.

 

Provision of online services and Web hosting (log files)

We process user data to be able to provide them with our online services. To this end, we process the user’s IP address, which is necessary in order to transfer the content and features of our online services to the user’s browser or device.

  • Types of data processed: Usage data (e.g., page impressions and time spent on pages, click paths, usage intensity and frequency, types of devices and operating systems used, interactions with content and features); metadata, communication data, and process data (e.g., IP addresses, time stamps, identification numbers, persons involved). Log data (e.g., log files concerning logins or the retrieval of data or access times).
  • Data subjects: Users (e.g., website visitors, users of online services).
  • Purposes of processing: Provision of our online services and user friendliness; information technology infrastructure (operation and provision of information systems and technical devices (computers, servers, etc.)). Security measures.
  • Retention and erasure: Erasure in accordance with the information contained in the section titled “Information on data storage and erasure”.
  • Legal bases: Legitimate interests (point (f) of Article 6(1) GDPR).

Further information on processing operations, procedures, and services:

  • Provision of online services via rented storage capacity: To provide our online services, we use storage and processing capacity and software that we rent or otherwise obtain from a relevant server provider (also referred to as a “Web hoster”); legal bases: legitimate interests (point (f) of Article 6(1) GDPR).
  • Collection of access data and log files: Access to our online services is logged in the form of “server log files”. Server log files may include the address and name of the websites and files retrieved, date and time of retrieval, volumes of data transferred, report of successful retrieval, browser type and version, the user’s operating system, referrer URL (the page visited beforehand) and typically IP addresses and the requesting provider. The server log files may be used, first, for security purposes, e.g., to prevent overloading of servers (particularly in the case of distributed denial-of-service (DDoS) attacks) and, second, to ensure server capacity utilization and stability; legal bases: legitimate interests (point (f) of Article 6(1) GDPR). Erasure of data: Log file information is stored for a maximum period of 30 days, after which it is erased or anonymized. Data that must be retained for a longer period for evidentiary purposes are exempt from erasure until the relevant incident has been clarified on a final basis.

 

Use of cookies

Cookies are small text files or other storage notes that store information on devices and read it out from there. This is done, for example, to store the log-in status for a user account, the contents of a shopping cart in an online store, or the content retrieved or features of an online service that are used. Cookies can also be used in relation to various matters, such as for purposes of the functionality, security, and convenience of online services and to prepare analyses of user streams.

Information on consent: We use cookies in accordance with the legal provisions. Therefore, we obtain advance consent from users except where consent is not required by law. In particular, permission is not necessary if storing and reading out the information, including through the use of cookies, is strictly necessary in order to provide users with a tele-media service (meaning our online services) that they have expressly requested. The fact that they are giving consent and that it can be withdrawn is communicated clearly to them in a form that includes the information on the relevant cookie usage.

Information on legal bases for purposes of data protection and privacy law: The legal basis for purposes of data protection and privacy law on which we process users’ personal data using cookies depends on whether we ask users for consent. If users accept, the legal basis for the use of their data is their stated consent. Otherwise, the data used via cookies are processed on the basis of our legitimate interests (e.g., in the cost-effective operation of our online services and improvement of the usability thereof) or, if this takes place within the scope of fulfillment of our contractual obligations, if the use of cookies is necessary in order to comply with our contractual obligations. We provide information on the purposes for which we use cookies elsewhere in this Data Protection and Privacy Statement or within the scope of our consent and processing procedures.

Duration of storage: With regard to the duration of storage, a distinction is made between the following types of cookies:

  • Temporary cookies (also known as session cookies): Temporary cookies are erased no later than when a user has left an online service and closed his or her device (e.g., browser or mobile app).
  • Persistent cookies: Persistent cookies are stored even after the device is closed. This makes it possible to store the log-in status, for example, and display preferred content directly if and when a user visits a website again. The user data collected using cookies may also be used to measure reach. Where we do not communicate any explicit information on the type and duration of storage of cookies to users (e.g., within the scope of obtaining consent), they should presume that cookies are persistent and that the duration of storage may be up to two years.

General information on withdrawal of consent and objections (opting out): Users can withdraw the consent they have given at any time and can also object to the processing of their data in accordance with the legal specifications, including using their browser’s privacy settings.

  • Types of data processed: Metadata, communication data, and process data (e.g., IP addresses, time stamps, identification numbers, persons involved). Usage data (e.g., page impressions and time spent on pages, click paths, usage intensity and frequency, types of devices and operating systems used, interactions with content and features).
  • Data subjects: Users (e.g., website visitors, users of online services).
  • Purposes of processing: Provision of our online services and user friendliness.
  • Legal bases: Legitimate interests (point (f) of Article 6(1) GDPR). Consent (point (a) of Article 6(1) GDPR).

Further information on processing operations, procedures, and services:

  • Processing of cookie data based on consent: We use a consent management solution in which users’ consent to the use of cookies or to the procedures and providers mentioned in the context of the consent management solution is obtained. This procedure serves for purposes of obtaining, logging, and managing consent and withdrawal thereof, particularly in relation to the use of cookies and similar technologies used to store, retrieve, and process information on users’ devices. Within the scope of this procedure, the consent of users to the use of cookies and the associated processing of information, including the specific processing operations and providers mentioned in the consent management procedure, is obtained. Users also have the ability to manage and withdraw their consent. The declarations of consent are stored to eliminate the need to solicit consent again and to permit documentation of consent in accordance with the legal requirements. They are stored on the server side and/or in a cookie (known as an “opt-in” cookie) or via similar technologies in order to permit the consent to be associated with a specific user or that user’s device. Where there is no specific information provided regarding the providers of consent management services, the following general information applies: The duration of storage of consent is up to two years. In the process, a pseudonymous user identifier is created and stored together with the time of consent, the information on the scope of consent (e.g., relevant categories of cookies and/or service providers) and information about the browser, the system, and the device used; legal bases: consent (point (a) of Article 6(1) GDPR).
  • Cookie opt-out: The footer of our website contains a link via which you can modify your cookie settings and withdraw the relevant consent; legal bases: legitimate interests (point (f) of Article 6(1) GDPR).
  • Usercentrics: Consent management: procedure for obtaining, logging, managing and withdrawing consent, particularly to the use of cookies and similar technologies used to store, retrieve, and process information on users’ devices; service provider: Usercentrics GmbH, Sendlinger Strasse 7, 80331 Munich, Germany; website: https://usercentrics.com/. Privacy policy: https://usercentrics.com/privacy-policy/.

 

Contact and inquiry management in the course of the application

When people contact us in the course of an application (e.g., by career portal, email, phone, or via social media) ), the data of the applicant will be processed to the extent necessary to carry out the application process. We collect different types of information. This includes in particular your personal data with contact information as well as a description of your education, work experience and skills. In addition, you have the option of providing us with electronically stored documents such as certificates or cover letters. Please note that CVs, references or other data you send us for the purposes of your application may also contain particularly sensitive data (Article 9 GDPR). We therefore recommend that you do not provide any information relating to particularly sensitive data (e.g. information on mental and physical health, racial or ethnic origin, political opinions, religious or philosophical beliefs, membership of a trade union or political party). If you provide us with this type of information, you expressly agree that we may process this data for the purpose of carrying out the application process. This data will be processed in accordance with this privacy policy and other relevant legislation.

  • Types of data processed: Inventory data (e.g., full name, date of birth, home address, contact information, etc.); contact information (e.g., mailing and e-mail addresses or phone numbers); content data (e.g., messages and posts in text form and the information concerning them, such as gender); usage data (e.g., page impressions and time spent on pages, click paths, usage intensity and frequency, types of devices and operating systems used, interactions with content and features). Metadata, communication data, and process data (e.g., IP addresses, time stamps, identification numbers, persons involved).
  • Data subjects: Applicants, Other parties to communication.
  • Purposes of processing: Carrying out the application process, Communication; organizational and administrative procedures; feedback (e.g., collecting feedback). Provision of our online services and user friendliness.
  • Retention and erasure: Erasure in accordance with the information contained in the section titled “Information on data storage and erasure”.
  • Legal bases: Legitimate interests (point (f) of Article 6(1) GDPR). Performance of contract and inquiries prior to entering into a contract (point (b) of Article 6(1) GDPR). Legal obligation (point (c) of Article 6(1) GDPR). Insofar as special categories of personal data (e.g. health data pursuant to Article 9 GDPR) are processed, the processing is carried out on the basis of point (b) of Article 9(2) GDPR for the exercise of rights or for the fulfillment of legal obligations under labor law, social security and social protection law or point (a) of Article 9(2) GDPR on the basis of your explicit consent

Further information on processing operations, procedures, and services:

  • Online career portal: When people contact us via our carrer portal we process the personal data you provide us to carry out the application process. This typically includes information such as name, contact information, and possibly further information such as comments or notes that is communicated to us. We use these data exclusively for the indicated purpose of contact and communication when is required for application process. The information you provide in your application will only be used by us for purposes related to assessing your interest in current or future employment and processing your application. This includes reviewing your application documents and the information you disclose in job interviews and selection procedures, for contacting you, in some cases for reimbursement of travel costs and for storing the information from your application that you have sent us unsolicited. Your data will also be forwarded to the relevant internal departments in order to check the content of your application. We evaluate the question of how you became aware of us as part of the advertising material controlling process; legal bases: Performance of contract and inquiries prior to entering into a contract (point (b) of Article 6(1) GDPR). Legal obligation (point (c) of Article 6(1) GDPR). Legitimate interests (point (f) of Article 6(1) GDPR). Insofar as special categories of personal data (e.g. health data pursuant to Article 9 GDPR) are processed, the processing is carried out on the basis of point (b) of Article 9(2) GDPR for the exercise of rights or for the fulfillment of legal obligations under labor law, social security and social protection law or point (a) of Article 9(2) GDPR on the basis of your explicit consent.
  • rexx Systems: Software for the provision of the online career portal; service provider: rexx systems GmbH, Süderstrasse 75-79, 20097 Hamburg; legal bases: Performance of a contract or inquiries prior to entering into a contract (point (b) of Article 6(1) GDPR). Legitimate interests (point (f) of Article 6(1) GDPR); website: www.rexx-systems.com/en/; privacy statement: www.rexx-systems.com/data-protection/. 

 

Contact and inquiry management in the course of the application of minors

If you are still a minor, i.e. have not yet reached the age of 18, and would like to apply to us, we require that you have the consent of your legal representatives (usually your parents). If you have not yet reached the age of 16, your application must be accompanied by a declaration of consent from your legal representatives. If we do not have this declaration of consent, your application cannot be considered and your data will be deleted immediately.

 

Videoconferences, online meetings, webinars, and screen sharing

We use platforms and applications from other providers (collectively “conference platforms”) for purposes of holding video and audio conferences, webinars, and other types of video and audio meetings (collectively “conferences”). We observe the legal specifications in selecting conference platforms and their services.

Data processed by conference platforms: In the context of participation in a conference, the conference platforms process the personal data of participants as mentioned below. The scope of the processing depends on factors including which data are specifically required in the context of a concrete conference (e.g., provision of login information or real names) and which optional information is provided by participants. In addition to processing to hold the conference, the participants’ data may also be processed by the conference platforms for security purposes or to optimize services. The data processed include personal information (first name, last name), contact information (e-mail address, phone number), login information (login codes or passwords), profile pictures, information about the person’s professional position/title or role, the IP address of the Internet access, information on participants’ devices, operating system, browser, and technical and language settings, information on content-related communication procedures, i.e., entries in chats and audio and video data, along with the use of other available features (such as surveys or polls). The content of the communications is encrypted to the extent provided in technical terms by the conference providers. If the participants are registered with the conference platforms as users, then additional data may be processed as agreed with the relevant conference provider.

Logging and recordings: If text entries, results of participation (e.g., in surveys or polls) and video or audio recordings are logged, this is communicated transparently to the participants in advance, and they are asked to consent where necessary.

Data protection measures of participants: With regard to the details of the processing of your data by the conference platforms, please note the latter’s data protection and privacy information and select the security and data protection and privacy settings that are optimal for you within the scope of the conference platform settings. Furthermore, please ensure data protection and privacy in the background of your images or recordings for the duration of a videoconference (e.g., by notifying others with whom you live, closing doors, and using any available technical features to blur your background). Links to conference rooms and login information must not be disclosed to unauthorized third parties.

Information on legal bases: Where we also process users’ data in addition to the conference platforms and request consent from users to the use of the conference platforms or certain features (e.g., consent to the recording of conferences), the legal basis of processing is this consent. Furthermore, our processing may be necessary in order to fulfill our contractual obligations (e.g., in participant lists, in the case of processing of the results of discussions or meetings, etc.). In all other respects, user data are processed on the basis of our legitimate interests in efficient and secure communication with the other parties to communications with us.

  • Types of data processed: Inventory data (e.g., full name, home address, contact information, client number, etc.); contact information (e.g., mailing and e-mail addresses or phone numbers); content data (e.g., messages and posts in text or image form and the information concerning them, such as information on authorship or the time of creation); usage data (e.g., page impressions and time spent on pages, click paths, usage intensity and frequency, types of devices and operating systems used, interactions with content and features); images and/or video recordings (e.g., photographs or video recordings of a person); audio recordings. Log data (e.g., log files concerning logins or the retrieval of data or access times).
  • Data subjects: Other parties to communication; users (e.g., website visitors, users of online services). Persons depicted.
  • Purposes of processing: Performance of contractual services and fulfillment of contractual obligations; communication. Office and organizational procedures.
  • Retention and erasure: Erasure in accordance with the information contained in the section titled “Information on data storage and erasure”.
  • Legal bases: Legitimate interests (point (f) of Article 6(1) GDPR).

Further information on processing operations, procedures, and services:

 

Web analysis, monitoring, and optimization

Web analysis (also known as “reach measurement”) serves to analyze the visitor streams to our online services and may encompass behavior, interests, or demographic information on visitors, such as age or gender, as pseudonymized values. We can use reach analysis to see, for example, the time at which our online services or their features or content are used most frequently or to invite people to use them again. It is also possible for us to track which areas require optimization.

In addition to Web analysis, we may also use test methods to test and optimize aspects such as different versions of our online services or their components.

Unless otherwise indicated below, profiles, meaning data compiled on a use operation, may be created for these purposes, and information may be stored in a browser or on a device and then retrieved. The information collected includes but is not limited to websites visited and elements used there, along with technical information such as the browser and computer system used and information on usage times. Where users have consented, either to us or the providers of the services used by us, to the collection of their location data, processing of location data is also possible.

Beyond that, users’ IP addresses are stored. However, we use an IP masking procedure (i.e., pseudonymization by truncating (shortening) the IP address) to protect users. In general, no real information pertaining to users (such as e-mail addresses or names) is stored in the context of Web analysis, A/B testing and optimization. Instead, this information is pseudonymized. This means that neither we nor the providers of the software used know the actual identity of the user. Instead, all that is known is the information stored in the users’ profiles for the purpose of the relevant operations.

Information on legal bases: Where we ask users for their consent to the use of third parties, the legal basis for data processing is consent. Otherwise, user data are processed on the basis of our legitimate interests (i.e., interest in efficient, cost-effective and user-friendly services). In this context, we would also like to point out the information on the use of cookies in this Data Protection and Privacy Statement.

  • Types of data processed: Usage data (e.g., page impressions and time spent on pages, click paths, usage intensity and frequency, types of devices and operating systems used, interactions with content and features). Metadata, communication data, and process data (e.g., IP addresses, time stamps, identification numbers, persons involved).
  • Data subjects: Users (e.g., website visitors, users of online services).
  • Purposes of processing: Reach measurement (e.g., access statistics, recognition of recurring visitors); profiles containing user-related information (creating user profiles). Provision of our online services and user friendliness.
  • Retention and erasure: Erasure in accordance with the information contained in the section titled “Information on data storage and erasure”.
  • Security measures: IP masking (pseudonymization of IP address).
  • Legal bases: Consent (point (a) of Article 6(1) GDPR). Legitimate interests (point (f) of Article 6(1) GDPR).

Further information on processing operations, procedures, and services:

  • Matomo: Matomo is a software program used for purposes of Web analytics and reach measurement. In the context of the use of Matomo, cookies are created and stored on the user’s device. The user data collected in the context of the use of Matomo are processed only by us and not shared with third parties. The cookies are stored for a maximum period of 13 months: https://matomo.org/faq/general/faq_146/; legal bases: consent (point (a) of Article 6(1) GDPR). Erasure of data: The cookies have a maximum storage period of 13 months.

 

Plugins and embedded functions and content

Our online services incorporate functional and content elements obtained from the servers of their respective providers (“third-party providers”). These may include but are not limited to graphics, videos, and maps (collectively “content”).

Incorporation of these elements always presupposes that the third-party providers of this content process the IP addresses of users, as without these IP addresses, they would be unable to transmit the content to the users’ browsers. This means the IP address is required in order to present this content or these functions. We strive to use only content whose respective provider uses the IP address solely to deliver the content. Third-party providers may moreover use what are known as pixel tags (invisible graphics also known as Web beacons) for statistical or marketing purposes. These pixel tags allow for analysis of information such as user traffic to the pages of this website. This pseudonymized information can furthermore be stored in cookies on the user’s device and may include items such as technical information on the browser and operating system, referring websites, the time of the visit, and further information on the use of our online services. It may also be associated with such information from other sources.

Information on legal bases: Where we ask users for their consent to the use of third parties, the legal basis for data processing is permission. Otherwise, user data are processed on the basis of our legitimate interests (i.e., interest in efficient, cost-effective and user-friendly services). In this context, we would also like to point out the information on the use of cookies in this Data Protection and Privacy Statement.

  • Types of data processed: Usage data (e.g., page impressions and time spent on pages, click paths, usage intensity and frequency, types of devices and operating systems used, interactions with content and features); metadata, communication data, and process data (e.g., IP addresses, time stamps, identification numbers, persons involved); inventory data (e.g., full name, home address, contact information, client number, etc.); contact information (e.g., mailing and e-mail addresses or phone numbers); content data (e.g., messages and posts in text or image form and the information concerning them, such as information on authorship or the time of creation). Location data (information on the geographic position of a device or person).
  • Data subjects: Users (e.g., website visitors, users of online services).
  • Purposes of processing: Provision of our online services and user friendliness.
  • Retention and erasure: Erasure in accordance with the information contained in the section titled “Information on data storage and erasure”.
  • Legal bases: Consent (point (a) of Article 6(1) GDPR). Legitimate interests (point (f) of Article 6(1) GDPR).

Further information on processing operations, procedures, and services:

Google Maps: We incorporate maps from the Google Maps service provided by Google. The data processed may include but are not limited to users’ IP addresses and location information; service provider: Google Cloud EMEA Limited, 70 Sir John Rogerson’s Quay, Dublin 2, Ireland; legal bases: consent (point (a) of Article 6(1) GDPR); website: https://mapsplatform.google.com/; privacy policy: https://policies.google.com/privacy. Basis for third-country transfers: Data Privacy Framework (DPF).