Privacy Policy

We, the REFLECTS GmbH, take the protection and security of your personal data very seriously. We adhere to the rules of applicable data protection laws, especially those of the Telemedia Act (TMG), the Federal Data Protection Act (BDSG) and the General Data Protection Regulation (DSGVO) and have designed our business processes - wherever possible - to collect or process as little personal data as possible. We are pleased that you are visiting our website. We respect your privacy. Data protection and data security when using our website are very important to us. With this privacy policy, we would like to inform you about the extent to which data is collected when using our website and for what purposes we use this data. We would also like to inform you about your rights in this regard.

Identity of the legal or natural person responsible

REFLECTS GmbH
Toyota Allee 54
50858 Köln
Deutschland
Telefon: +49 (0) 22 34 / 99 00-0
Fax: +49 (0) 22 34 / 99 00-100
E-Mail: info@reflects.com
Court of Registration: Amtsgericht Köln
Registration number: HRB 208 18

The external data protection officer can be reached at

SBB-Consulting UG (hb)
Herr Johann Böhmer
Salierring 32
50677 Köln
Email: dsb@reflects.de

Processing purposes and legal basis

Data processing includes, among other things, the purpose of executing and managing contractually agreed deliveries or services.

The processing of your data is necessary under Article 6(1)(f) of the DSGVO to safeguard our legitimate interests or those of a third party.

Categories of data

We process the following categories of data:

  • Address data
  • Contact data
  • Communication data
  • Other personal data

Data sources:

  • Collection from the customer or employee or applicant
  • Collection from external entities
  • Collection from publicly accessible sources

Recipients:

Internal departments, and as part of the processing purposes, we will transmit your data to other companies if necessary to carry out the purposes.

Retention period:

Data will be stored until revoked by the data subject. However, a maximum of 10 years, except for data subject to statutory retention periods.

Data subject rights

Rights of data subjects:

Subject to the legal requirements, you have the following rights under Articles 15 to 22 of the DSGVO: the right to access, rectification, erasure, restriction of processing, and data portability.

Furthermore, pursuant to Article 14(2)(c) in conjunction with Article 21 of the DSGVO, you have the right to object to processing based on Article 6(1)(f) of the DSGVO.

For questions regarding the collection, processing, or use of your personal data, for information, correction, blocking, or deletion of data, as well as the withdrawal of consent granted or objection to specific data usage, please contact us directly using the contact details in our imprint.

Right to lodge a complaint

With the Supervisory Authority under Article 77 of the DSGVO, you have the right to lodge a complaint with the supervisory authority if you believe that the processing of your personal data is not lawful. The address of the supervisory authority responsible for our company is as follows:

State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia Kavalleriestraße 2-4, 40213 Düsseldorf Telephone: 02 11/3 84 24 – 0 Fax: 02 11/3 84 24 - 10 Email: poststelle@ldi.nrw.de


Cookies

a. Type and purpose of processing

Like many other websites, we also use so-called "cookies."

Cookies are simple files that store information about our website and your usage. These small files are automatically created by your browser when using our website and are locally stored on your respective device. This does not mean that we have immediate knowledge of your identity. The use of cookies is intended to make your use of our service more pleasant.

Therefore, we fundamentally differentiate between technically necessary and unnecessary cookies:<

Technically necessary cookies ("First party cookies")

These are required for the operation of a website and are essential for navigating and using its functions. These cookies are not permanently stored on your computer or device and are deleted when you close the browser. They are known as session cookies.

The following technically necessary cookies are used on our site:

NameProviderType and Purpose of CookiesRetention Period
TimezoneShopware AGTime zone detectionSession
session-Shopware AGA session cookie that maintains a session (visit to the website) and serves as an identifier between the browser and the serverSession
csrf[frontend.compare.offcanvas]Shopware AGThis cookie helps secure the website and its users from CSRF (Cross-Site Request Forgery) attacks.Session
csrf[frontend.checkout.switch-language]Shopware AGThis cookie assists in securing the website and its users against CSRF (Cross-Site Request Forgery) attacks.Session
csrf[frontend.stock.index]Shopware AGThis cookie helps secure the website and its users against CSRF (Cross-Site Request Forgery) attacks.Session
csrf[frontend.store-api.proxy]Shopware AGThis cookie helps secure the website and its users against CSRF (Cross-Site Request Forgery) attacks.Session

Temporary Cookies

However, non-essential cookies typically include Functional Cookies, Performance Cookies, and Marketing Third Party Cookies, which allow us to, for example, to collect and count the number of visitors and traffic sources, thereby measuring and improving the performance of the website. They also help identify whether certain pages encounter issues or errors, which pages are the most popular, and how visitors navigate the website.

Functional cookies

Functional cookies are used to store user input, such as usernames or language preferences, to provide enhanced and personalized features to website visitors based on this information.

Performance cookies

Performance cookies are used to track visits and individual activities on websites. They are used to statistically record and evaluate the usage of websites.

Marketing & third Party cookies

Marketing & Third party cookies, among other sources, come from external advertising companies and are used to gather information about the websites visited by the user in order to create, for example, targeted advertising for the user.

The following non-essential cookies are used by us:

NameProviderType and Purpose of CookiesRetention Period
cookie-preferenceShopware AGThis cookie stores the visitor's cookie preferences, so that the cookie consent banner is not displayed upon revisiting the website.30 days
matomo-analytics-enabledMatomoThis cookie stores your decision regarding the use of the Matomo service.Session
_pk_ses*MatomoThese cookies allow for the assignment of a unique session ID, enabling the analysis of user behavior on the website.Session
_pk_id*MatomoThis cookie is used to store details about the user, such as the unique visitor ID (anonymized).13 months
_pk_ref*MatomoThis cookie is used to store attribution information that identifies the referrer of the website's original visit.6 months
MATOMO_SESSIDMatomoIt does not contain data used for identifying visitors and is categorized as 'Essential'.14 days
google-analytics-enabledGoogleThis cookie stores your decision regarding the use of the Google Analytics service.1 month
_gaGoogleCookie for collecting statistics about website usage with the Google Analytics service. It generates a randomly generated user ID, allowing Google Analytics to recognize recurring visitors on this website and aggregate data from previous visits.2 years
_swag_ga_ga_gidGoogleThis cookie is required by the Google Analytics service in use. It is used to recognize individual website visitors based on an anonymized numerical combination.24 hours
_swag_ga_gaGoogleThis cookie is required by the Google Analytics service in use. It is used to recognize individual website visitors based on an anonymized numerical combination.24 hours
_gat_gtag_UA*GoogleThis Google Universal Analytics cookie is used to throttle the request rate of data and limit collection on heavily trafficked websites. It prevents the transmission of data to Google Analytics.Session
wbm-tagmanager-enabledGoogleAcceptance of Google TagManager Cookies.3 months
IDE or ANIDGoogle / DoubleclickThe 'ANID' and 'IDE' cookies are used to display Google ads on websites that are not owned by Google. If you have personalized advertising enabled, the 'ANID' cookie is used to store this preference.Up to 2 years
DSIDGoogleThis cookie is used to identify a logged-in user on non-Google websites and to store whether the user has consented to personalized advertising.2 weeks
_gat_gtag_*GoogleThis cookie is required by the Google Analytics service in use. It is primarily used for statistical purposes to capture and analyze user interactions on a website.Session
ar_debugGoogleThis Google cookie is used for storing and tracking conversions.1 year
__Secure-3PSIDCCYouTube / GoogleThis cookie is used by YouTube to create a user profile and display relevant and personalized Google advertisements to the user.2 years
__Secure-3PSIDTSYouTube / GoogleThis cookie is used by YouTube to create a user profile and display relevant and personalized Google advertisements to the user.2 years
__Secure-1PSIDTSYouTube / GoogleThis cookie is used by YouTube to create a user profile and display relevant and personalized Google advertisements to the user.2 years
__Secure-3PSIDYouTube / GoogleThis cookie is used by YouTube to create a user profile and display relevant and personalized Google advertisements to the user.2 years
__Secure-1PSIDCCYouTube / GoogleThis cookie is used by YouTube to create a user profile and display relevant and personalized Google advertisements to the user.2 years
SIDCCYouTube / GoogleThese cookies are set by YouTube and helps authenticate the user, prevent fraudulent use of login credentials, and protect user data from unauthorized access.2 years
__Secure-3PAPISIDYouTube / GoogleThis cookie is used by YouTube to create a user profile and display relevant and personalized Google advertisements to the user.2 years
__Secure-1PAPISIDYouTube / GoogleThis cookie is used by YouTube to create a user profile and display relevant and personalized Google advertisements to the user.2 years
HSIDYouTube / GoogleThis cookie is for security purposes, assisting in user authentication, fraud prevention, and protection during interactions. This cookie stores the Google account ID and the user's last login time in digitally signed and encrypted form.2 years
SAPISIDYouTube / GoogleThis cookie is for security purposes, assisting in user authentication, fraud prevention, and protection during interactions.2 years
SSIDYouTube / GoogleThis cookie is for security purposes, helping to authenticate users, prevent fraud, and provide protection during interactions.2 years
APISIDYouTube / GoogleThis Google cookie collects visitor information for videos played on YouTube.2 years
__Secure-1PSIDYouTube / GoogleThis cookie is used by YouTube to create a user profile and display relevant and personalized Google advertisements to the user.2 years
SIDYouTube / GoogleThis cookie is for security purposes, assisting in user authentication, fraud prevention, and providing protection during interactions. This cookie stores the user's Google account ID and the last login time in digitally signed and encrypted form.2 years
AECYouTube / GoogleThis cookie is used to prevent spam, fraud, and abuse. This cookie prevents malicious websites from acting on behalf of the user without their knowledge.6 months
1P_JARYouTube / GoogleThis cookie is used by YouTube to create a user profile and display relevant and personalized Google advertisements to the user.1 month
OGPCYouTube / GoogleThe OGPC cookie is used by Google for the functionality of Google Maps.Session
DVYouTube / GoogleThe DV cookie by Google is primarily used for advertising purposes. Its main function is to support ad delivery and retargeting.24 hours
NIDYouTube / GoogleThis cookie is used to display Google ads for logged-in users in Google services.2 years
OTZYouTube / GoogleThis cookie is used by Google to track information about website traffic.Up to 2 years
CONSENTYouTube / GoogleThis cookie stores the user's cookie decisions.2 years
SOCSYouTube / GoogleThis cookie stores the user's cookie decisions.13 months

b. Legal basis for processing

The use of technically necessary cookies ("First party cookies") is possible without the consent of the website visitor and is subject to a legitimate interest in the economic operation and optimization of our website and services, in accordance with Art. 6(1) sentence 1 lit. f DSGVO.

The use of non-essential cookies, such as functional cookies, performance cookies, and marketing & third party cookies, requires the consent of the website visitor, in accordance with Art. 6(1) sentence 1 lit. a DSGVO.

c. Categories of data

  • IP address
  • Used browser
  • Operating system used
  • Internet connection
  • Session ID of the cookie

d. Recipients

Recipients of the data are internal employees of Reflects GmbH and Google as a data processor. For this purpose, we have entered into a corresponding Data Processing Agreement with all processing companies.

e. Data retention periods

The user can configure their web browser to prevent the storage of cookies on their device in general or to prompt them each time to consent to the setting of cookies. Once set, the user can delete cookies at any time. The process for doing so is described in the help function of the respective web browser. Disabling cookies in general may potentially lead to limitations in the functionality of this website.

f. Legal / contractual requirement

The provision of your personal data in cookies is voluntary for non-essential cookies, solely based on your consent (so-called Opt-In cookies). You can also prevent the use of pre-set, technically necessary cookies (so-called Opt-Out cookies) through your browser settings. However, without consent, the service and functionality of our website cannot be guaranteed. Additionally, individual services and features may not be available or may be limited.

g.  Third-country transfer

Data processing does not occur outside of the European Union (EU) or the European Economic Area (EEA).

h. Withdrawal of consent

You can withdraw your consent for all cookies at any time with effect for the future by adjusting your browser settings.

i. Automated decision-making and profiling

As a responsible company, we refrain from using automated decision-making or profiling in the collection of cookies.

Usage of Google Analytics

a. Type and purpose of processing

This website uses Google Analytics, a web analytics service provided by Google LLC, Gordon House, 4 Barrow Street, Dublin, D04 E5W5, Ireland. Google Analytics uses so-called "cookies," which are text files stored on your computer that enable an analysis of your use of the website. The information generated by the cookie about your use of this website is usually transmitted to a Google server in the United States and stored there. However, due to the activation of IP anonymization on these web pages, your IP address will be shortened by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area before transmission. Only in exceptional cases will the full IP address be sent to a Google server in the USA and shortened there. On behalf of the operator of this website, Google will use this information to evaluate your use of the website, to compile reports on website activities, and to provide further services related to website usage and internet usage to the website operator. The IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data. The purposes of data processing are to evaluate the use of the website and to compile reports on website activity. Based on the use of the website and the internet, further related services are then to be provided.

b. Legal basis for processing

The processing of the data is based on the user's consent (Art. 6(1)(a) DSGVO).

c. Categories of data

IP address (shortened/anonymized)

d. Recipients

  • Employees of the IT and Marketing Departments of the Reflects GmbH
  • Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland

e. Data retention periods

Data in this context is only processed as long as the corresponding consent is in place. Afterward, they will be deleted unless there are legal retention obligations. To contact us regarding this matter, please use the contact details provided at the beginning of this privacy policy.

f. Legal / contractual requirement

The provision of your personal data is voluntary, based solely on your consent. If you prevent access, it may result in limitations in the functionality of the website.

g. Third-country transfer

Data processing does not occur outside of the European Union (EU) or the European Economic Area (EEA).

h. Withdrawal of consent

You can withdraw your consent for the storage of your personal data at any time with effect for the future. You can inform us of your withdrawal through the contact information provided at the beginning of this privacy policy.

You can prevent the storage of cookies by adjusting your browser software accordingly. However, please note that in this case, you may not be able to use all the features of this website to their full extent. Additionally, you can prevent Google from collecting and processing the data generated by the cookie and related to your use of the website (including your IP address) by downloading and installing the browser plugin available at the following link:

"Browser Add-On to Deactivate Google Analytics."

i. Automated decision-making and profiling

With the help of the tracking tool Google Analytics, the behavior of website visitors can be evaluated, and their interests can be analyzed. For this purpose, we create a pseudonymous user profile.


Google Tag Manager

a. Type and purpose of processing

Use of Google Tag Manager: Google Tag Manager is a solution that allows marketers to manage website tags through an interface. The Tag Manager tool itself (which implements the tags) is a cookie-less domain and does not collect personal data. The tool triggers other tags that may, in turn, collect data. Google Tag Manager does not access this data. If deactivation has been made at the domain or cookie level, it will remain in effect for all tracking tags implemented with Google Tag Manager: https://www.google.com/analytics/terms/tag-manager/.

b. Legal basis for processing

The processing of the data is based on the user's consent (Art. 6(1)(a) DSGVO).

c. Categories of data tags

Tags

d.  Recipients

Recipients of the data are internal employees of IT and Marketing Departments of the Reflects GmbH and Google as data processor. We have concluded the corresponding Data Processing Agreement with Google for this purpose.

e. Data retention periods

Data in this context is only processed as long as the corresponding consent is in place. Afterward, they will be deleted unless there are legal retention obligations. To contact us regarding this matter, please use the contact details provided at the beginning of this privacy policy.

f. Legal / contractual requirement

The provision of your personal data is voluntary, based solely on your consent. If you prevent access, it may result in limitations in the functionality of the website.

g. Third-country transfer

Data processing does not occur outside of the European Union (EU) or the European Economic Area (EEA).

h. Withdrawal of consent

You can withdraw your consent for the storage of your personal data at any time with effect for the future. You can inform us of your withdrawal through the contact information provided at the beginning of this privacy policy.

You can prevent the storage of cookies by adjusting your browser software accordingly. However, please note that in this case, you may not be able to use all the features of this website to their full extent.

i. Profiling

With the help of the Google Tag Manager tool, the behavior of website visitors can be evaluated, and their interests can be analyzed.


Matomo

a. Type and purpose of processing

This website uses Matomo (formerly Piwik), an open-source software for the statistical analysis of visitor access. The provider of the Matomo software is InnoCraft Ltd., 150 Willis St, 6011 Wellington, New Zealand. Matomo uses so-called cookies, which are text files that are stored on your computer and enable an analysis of your use of the website. The information generated by the cookie about your use of the internet offering is stored on a server in Germany. The IP address is anonymized immediately after processing and before storage. You have the option to prevent the installation of cookies by adjusting your browser software settings. Please note that with the appropriate settings, not all functions of this website may be available. You can decide whether a unique web analysis cookie may be stored in your browser to enable the website operator to collect and analyze various statistical data. Further information about the privacy settings of the Matomo software can be found at the following link: https://matomo.org/docs/privacy/

b.  Legal basis for processing

The processing of data is based on the user's consent (Art. 6(1)(a) DSGVO).

c.  Categories of data

  • IP Address (shortened/anonymized)
  • URLs
  • Page titles
  • Referrer URLs
  • Geolocation based on IP address
  • Tracking cookie IDs
  • Onsite search
  • Custom events, dimensions, and variables: login, shopping cart
  • User ID
  • E-commerce order IDs
  • Downloads
  • Page generation times
  • Browser language
  • User agent, device, and operating system

d.  Recipients

Recipients of the data are internal employees of IT and Marketing Departments of the Reflects GmbH.

e. Retention period

Data is deleted as soon as it is no longer required for our recording purposes. In our case, this occurs after the following period: 24 months.

a.  Legal/Contractual requirements

The provision of your personal data is voluntary, solely based on your consent. If you prevent access, it may lead to limitations in the functionality of the website.

f.  Third-country transfer

Although Matomo is headquartered in New Zealand, all data is hosted by Matomo on our own servers located in Germany and transferred to our own databases. Therefore, processing does not occur outside the European Union (EU) or the European Economic Area (EEA).

g.  Revocation of consent

You can revoke your consent for the storage of your personal data at any time with future effect. You can inform us of your revocation at any time using the contact information provided at the beginning of this privacy policy.

You can prevent the storage of cookies by adjusting your browser software settings; however, we would like to point out that in this case, you may not be able to fully use all functions of this website.

h. Automated decision-making and profiling

With the help of the Matomo tracking tool, the behavior of website visitors can be evaluated, and their interests analyzed. To do this, we create a pseudonymous user profile.


Social Media

X (formerly Twitter)

a.     Nature and purpose of data processing

We appreciate your interest in our presence on X (formerly Twitter). We would like to provide you with an overview of the data collected, used, and stored by us there. Social networks can generally comprehensively analyze your user behavior when you visit their website or a website with integrated social media content (e.g., like buttons or advertising banners). By visiting our social media presence on X (formerly Twitter), numerous data protection-relevant processing operations are triggered. In detail:

If you are logged into your X (formerly Twitter) account and visit our social media presence, X (formerly Twitter) can associate this visit with your user account. However, your personal data may also be collected even if you are not logged in or do not have an X (formerly Twitter) account. In this case, data may be collected, for example, through cookies stored on your device or by capturing your IP address. With the help of the data collected in this way, X (formerly Twitter) can create user profiles in which your preferences and interests are stored. This enables you to be shown interest-based advertising on and off X (formerly Twitter). If you have an X (formerly Twitter) account, interest-based advertising can be displayed on all devices on which you are logged in or have been logged in. Please note that we cannot fully trace all processing processes on X (formerly Twitter). Therefore, additional processing operations by X (formerly Twitter) may be carried out. For details, please refer to the terms of use and privacy policy of X (formerly Twitter).

b.  Legal Basis for data processing

The processing is carried out in accordance with Art. 6(1)(f) DSGVO on the basis of our legitimate interest in having contact with our customers. The analysis processes initiated by X (formerly Twitter) may be based on different legal bases that X (formerly Twitter) must specify (e.g., consent within the meaning of Art. 6(1)(a) DSGVO).

c. Categories of data

For the specific data collected and how it is used, please refer to X's (formerly Twitter's) privacy policy. Twitter: https://twitter.com/privacy

d. Recipients

  • Employees of the IT and Marketing Department of our own company.
  • X (formerly Twitter)

e. Retention period

After the purpose of data collection is no longer applicable, and the use of X (formerly Twitter) by us has ended, the data collected in this context will be deleted.

f. Legal/Contractual requirements

Providing your personal data is voluntary. Without providing your personal data, we cannot grant you access to our offered content and services.

h. Third-country transfer

The processing does not occur outside the European Union (EU) or the European Economic Area (EEA).

i. Revocation of consent

You can withdraw your consent to the storage of your personal data at any time with future effect. You can inform us of your withdrawal using the contact information provided at the beginning of this privacy policy.

j. Automated decision-making and profiling

As a responsible company, we refrain from automated decision-making or profiling in this data processing.

Facebook

a. Nature and purpose of data processing

We appreciate your interest in our presence on Facebook. We would like to provide you with an overview of the data collected, used, and stored by us on this platform.

Social networks typically have the capability to extensively analyze your user behavior when you visit their website or a website with integrated social media content (e.g., Like buttons or banners). Visiting our social media presence on Facebook triggers various data processing activities that are relevant to data privacy. In particular:

If you are logged into your Facebook account and visit our social media presence, Facebook can associate this visit with your user account. Your personal data may also be collected even if you are not logged in or do not have a Facebook account. In such cases, data collection may occur through means like cookies stored on your device or by capturing your IP address. With the data collected in this way, Facebook can create user profiles that include your preferences and interests. This allows for interest-based advertising to be displayed to you both within and outside of Facebook. If you have a Facebook account, interest-based advertising can be displayed on all devices on which you are logged in or have been logged in. Please note that we cannot track all data processing activities carried out by Facebook. Additional processing activities by Facebook may therefore be possible. For more details, refer to Facebook's terms of use and privacy policies.

b. Legal basis for data processing

The processing is carried out in accordance with Art. 6(1)(f) DSGVO on the basis of our legitimate interest in contacting our customers. The analysis processes initiated by Facebook may be based on different legal grounds as specified by Facebook (e.g., consent pursuant to Art. 6(1)(a) DSGVO).

For specific details on the data collected and how it is used, please refer to Facebook's privacy policy: Facebook: http://www.facebook.com/policy.php

c. Recipients

  • Employees of the Marketing and IT departments of our own company
  • Facebook

e. Retention period

After the purpose has been achieved, and upon the conclusion of our use of Facebook, the data collected in this context will be deleted.

f. Legal/Contractual requirement

The provision of your personal data is voluntary. Without providing your personal data, we cannot grant you access to our offered content and services.

g. Third-country transfer

The processing does not take place outside the European Union (EU) or the European Economic Area (EEA).

h. Revocation of consent

You can withdraw your consent to the storage of your personal data at any time with effect for the future. You can inform us of your withdrawal at any time using the contact details provided at the beginning of this privacy policy.

i. Automated decision-making and profiling

As a responsible company, we refrain from automated decision-making or profiling in this data processing.

LinkedIn

a. Nature and purpose of processing

We appreciate your interest in our presence on LinkedIn. We would like to provide you with an overview of the data collected, used, and stored by us there. Social networks typically comprehensively analyze your user behavior when you visit their website or a website with integrated social media content (e.g., like buttons or banners). By visiting our social media presence on LinkedIn, numerous data protection-relevant processing operations are triggered. In detail:

If you are logged into your LinkedIn account and visit our social media presence, LinkedIn can associate this visit with your user account. Your personal data may also be collected even if you are not logged in or do not have an account on LinkedIn. In this case, data collection may occur, for example, through cookies stored on your device or by capturing your IP address. With the data collected in this way, LinkedIn can create user profiles in which your preferences and interests are stored. This enables interest-based advertising to be displayed to you both within and outside of LinkedIn. If you have a LinkedIn account, interest-based advertising can be displayed on all devices on which you are logged in or have been logged in. Please note that we cannot trace all processing processes on LinkedIn. Therefore, additional processing operations by LinkedIn may be carried out. For details, please refer to LinkedIn's terms of use and privacy policy.

b. Legal basis for processing

Processing is carried out in accordance with Art. 6(1)(f) DSGVO based on our legitimate interest in contacting our customers. The analysis processes initiated by LinkedIn may be based on different legal grounds as specified by LinkedIn (e.g., consent pursuant to Art. 6(1)(a) DSGVO).

c. Categories of data

For specific details on the data collected and how it is used, please refer to LinkedIn's privacy policy: LinkedIn: https://www.linkedin.com/legal/privacy-policy

d. Recipients

  • Employees of the Marketing and IT departments of your our company
  • LinkedIn

e. Retention period

After the purpose has been achieved, and upon the conclusion of our use of LinkedIn, the data collected in this context will be deleted.

f. Legal / Contractual requirement

The provision of your personal data is voluntary. Without providing your personal data, we cannot grant you access to our offered content and services.

g. Third-country transfer

The processing does not take place outside the European Union (EU) or the European Economic Area (EEA).

h. Revocation of consent

You can withdraw your consent to the storage of your personal data at any time with effect for the future. You can inform us of your withdrawal at any time using the contact details provided at the beginning of this privacy policy.

i. Automated decision-making and profiling

As a responsible company, we refrain from automated decision-making or profiling in this data processing.

YouTube

a. Nature and purpose of processing

We appreciate your interest in our presence on YouTube. We would like to provide you with an overview of the data collected, used, and stored by us there. Social networks typically comprehensively analyze your user behavior when you visit their website or a website with integrated social media content (e.g., like buttons or banners). By visiting our social media presence on YouTube, numerous data protection-relevant processing operations are triggered. In detail:

If you are logged into your YouTube account and visit our social media presence, YouTube can associate this visit with your user account. Your personal data may also be collected even if you are not logged in or do not have an account on YouTube. In this case, data collection may occur, for example, through cookies stored on your device or by capturing your IP address. With the data collected in this way, YouTube can create user profiles in which your preferences and interests are stored. This enables interest-based advertising to be displayed to you both within and outside of YouTube. If you have a YouTube account, interest-based advertising can be displayed on all devices on which you are logged in or have been logged in. Please note that we cannot trace all processing processes on YouTube. Therefore, additional processing operations by YouTube may be carried out. For details, please refer to YouTube's terms of use and privacy policy.

b. Legal basis for processing

Processing is carried out in accordance with Art. 6(1)(f) DSGVO based on our legitimate interest in contacting our customers. The analysis processes initiated by YouTube may be based on different legal grounds as specified by YouTube (e.g., consent pursuant to Art. 6(1)(a) DSGVO).

c. Categories of data

For specific details on the data collected and how it is used, please refer to YouTube's privacy policy: YouTube: https://policies.google.com/privacy

d. Recipients

  • Employees of the Marketing and IT departments of our own company
  • Google

e. Retention period

After the purpose has been achieved, and upon the conclusion of our use of YouTube, the data collected in this context will be deleted.

f. Legal / Contractual requirement

The provision of your personal data is voluntary. Without providing your personal data, we cannot grant you access to our offered content and services.

g. Third-country transfer

The processing does not take place outside the European Union (EU) or the European Economic Area (EEA).

h. Revocation of consent

You can withdraw your consent to the storage of your personal data at any time with effect for the future. You can inform us of your withdrawal at any time using the contact details provided at the beginning of this privacy policy.

i. Automated decision-making and profiling

As a responsible company, we refrain from automated decision-making or profiling in this data processing.

Embedded YouTube Videos

Our website uses the YouTube embedding feature to display and play videos from YouTube. We use the enhanced privacy mode, which, according to the provider's information, only starts storing user information when the video is played. As soon as the playback of the embedded video begins, YouTube uses cookies to collect information about user behavior. We use YouTube's No-Cookies feature, meaning we have activated Enhanced Privacy, and videos are accessed not via youtube.com, but via youtube-nocookie.com. According to YouTube, these serve, among other things, to capture video statistics, improve user-friendliness, and prevent abusive actions. Regardless of whether the embedded videos are played back, a connection to the Google "DoubleClick" network is established every time this website is accessed, which can trigger further data processing operations without our influence. For more information on data protection at YouTube, please refer to the provider's privacy policy: https://www.google.de/intl/de/policies/privacy/

Links to other websites

Our online offering contains links to other websites. We have no influence on whether their operators comply with data protection regulations. We therefore recommend that you also inform yourself about the respective privacy statements on other websites.

Privacy policy for job applicants

When you apply to us, we will use only the information provided by you. In addition to the legal bases mentioned above, this is done to carry out pre-contractual measures in accordance with Art. 6(1)(b) DSGVO and to make a decision about the establishment of an employment relationship in accordance with § 26(1) sentence 1 BDSG (German Federal Data Protection Act).

Within our company, only those persons involved in the application process have access to your data.

If your application leads to the establishment of an employment relationship, your personal data will continue to be processed for the purpose of conducting the employment relationship.>

If your application does not lead to the establishment of an employment relationship, your personal data will continue to be processed after the end of the application process based on legitimate interests, e.g., for the assertion or defense of legal claims, and will be deleted after the cessation of our legitimate interests as well as the expiration of statutory retention periods. This is usually the case three months after rejection, unless you have given us consent for longer storage.

Information about your rights

Right to information in accordance with Art. 15 DSGVO:

You have the right to request information, free of charge, about whether and what data about you is stored and for what purpose the storage is taking place.

Right to rectification in accordance with Art. 16 DSGVO:

You have the right to promptly request the correction of incorrect personal data. Taking into account the purposes of processing, you have the right to request the completion of incomplete personal data – also by means of a supplementary declaration.

Right to erasure ("right to be forgotten") in accordance with Art. 17 DSGVO:

You have the right to request the responsible party to delete your data immediately. The responsible party is obligated to delete personal data immediately if one of the following reasons applies:

  1. The purposes for which the personal data was collected are no longer relevant.
  2. You revoke your consent to the processing, and there is no other legal basis for processing.
  3. You object to the processing, and there is no overriding legal basis for processing.
  4. The personal data has been unlawfully processed.
  5. Deletion of personal data is required to fulfill a legal obligation under Union law or the law of the Member States to which the responsible party is subject.
  6. The personal data was collected in relation to information society services offered pursuant to Article 8(1).

Right to restriction of processing in accordance with Art. 18 DSGVO & § 35 BDSG:

You have the right to request a restriction of processing if one of the following conditions is met:

  1. The accuracy of the personal data is contested.
  2. Processing is unlawful, but you reject deletion.
  3. Personal data is no longer needed for processing purposes, but you need it to assert, exercise, or defend legal claims.
  4. You have objected to processing under Art. 21(1) DSGVO. As long as it has not been determined whether the legitimate reasons of the responsible party prevail over yours, processing is restricted.

Right to data portability in accordance with Art. 20 DSGVO:

You have the right to receive your data in a structured, common, and machine-readable format from the responsible party. You also have the right to transmit this data to another controller without hindrance by us.

Right to object in accordance with Art. 21 DSGVO:

To exercise this right, please contact the responsible party (see above). Complaints to the Supervisory Authority in accordance with Art. 13(2)(d), 77 DSGVO in conjunction with § 19 BDSG: If you believe that the processing of your data violates the DSGVO, you have the right to lodge a complaint with the competent supervisory authority for data protection.

Revocation of consent in accordance with § 26(2) BDSG:

If the processing is based on your consent in accordance with § 26(2) BDSG, you are entitled to withdraw your purpose-bound consent at any time without affecting the legality of the processing carried out on the basis of the consent until the withdrawal.

Our right to change the policy

Since changes in the law or changes in our internal company processes may make it necessary to adapt this privacy policy, we ask you to read this privacy policy regularly. The privacy policy can be accessed at any time at the FOLLOWING LINK. We reserve the right to amend these guidelines at any time in compliance with data protection regulations.


December 2023