Privacy Policy
We are very pleased that you have shown interest in our company. Data protection is a particularly high priority for the management of Amperecloud GmbH. The websites of Amperecloud GmbH can be used without providing personal data; however, if a data subject wishes to use special corporate services via our website, the processing of personal data may become necessary. If the processing of personal data is required and there is no legal basis for such processing, we generally obtain the consent of the data subject.
1. Definitions
The privacy policy of Amperecloud GmbH is based on the terms used by the European legislator in adopting the General Data Protection Regulation (GDPR). Our privacy policy is intended to be readable and understandable for the public as well as for our customers and business partners. To ensure this, we would first like to explain the terminology we use.
In this privacy policy, we use the following terms, among others:
a) Personal data
Personal data means any information relating to an identified or identifiable natural person (“data subject”). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to that natural person’s physical, physiological, genetic, mental, economic, cultural, or social identity.
b) Data subject
The data subject is any identified or identifiable natural person whose personal data is processed by the controller.
c) Processing
Processing means any operation or set of operations performed on personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
d) Restriction of processing
Restriction of processing means marking stored personal data with the aim of limiting its processing in the future.
e) Profile creation
Profiling means any form of automated processing of personal data that uses personal data to evaluate certain personal aspects of a natural person, in particular to analyse or predict aspects related to that person’s work performance, economic situation, health, personal preferences, interests, reliability, behaviour, location, or movements.
f) Pseudonymisation
Pseudonymisation means processing personal data in such a way that the data can no longer be attributed to a specific person without the use of additional information, provided that this additional information is kept separately and is subject to technical and organisational measures to ensure that the personal data is not attributed to an identified or identifiable natural person.
g) Controller or controller responsible for the processing.
The controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of processing personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for their nomination may be laid down by Union or Member State law.
h) Processor
The processor is a natural or legal person, public authority, agency, or other body that processes personal data on behalf of the controller.
i) Recipient
A recipient is a natural or legal person, a public authority, an agency or another body to whom personal data are disclosed, whether or not it is a third party. However, public authorities that may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law are not regarded as recipients; the processing of those data by those authorities is carried out in compliance with the applicable data protection rules in line with the purposes of the processing.
j) Third parties
A third party is any natural or legal person, public authority, agency or other body other than the data subject, the controller, the processor, and the persons who, under the direct authority of the controller or processor, are authorised to process personal data.
k) Consent
The data subject’s consent is any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which they, by a statement or by a clear affirmative action, signify their agreement to the processing of their personal data.
2. Name and address of the controller
The controller within the meaning of the General Data Protection Regulation (GDPR), other data protection laws applicable in the Member States of the European Union, and other provisions relating to data protection is:
Amperecloud GmbH
Rosa-Luxemburg-Str. 14
10178 Berlin
Deutschland
Phone: +49 (0) 30 549 091 439
Email: [email protected]
Website: www.amperecloud.com
3. Cookies
Cookies are used on the websites of Amperecloud GmbH. Cookies are text files that are stored on a computer system via an internet browser.
Many websites and servers use cookies. Many cookies contain a so‑called cookie ID. A cookie ID is a unique identifier of the cookie. It consists of a string of characters that allows websites and servers to associate it with the specific internet browser in which the cookie was stored. In this way, visited websites and servers can distinguish the individual browser of the data subject from other internet browsers that contain different cookies. A specific internet browser can be recognized and identified by means of the unique cookie ID.
By using cookies, Amperecloud GmbH can offer users of this website more user‑friendly services that would not be possible without cookies.
With the help of a cookie, the information and offers on our website can be optimized for the user. As already mentioned, cookies enable us to recognize users of our website. The purpose of this recognition is to make it easier for users to use our website. For example, a website user who uses cookies does not have to enter access data every time they visit the website, because the website takes this over and the cookie is therefore stored on the user’s computer system. Another example is the shopping cart cookie in an online shop. The online shop remembers the items that a customer has placed in the virtual shopping cart via a cookie.
Data subjects can prevent cookies from being set via our website at any time by adjusting the settings of the internet browser they use, and can thus permanently refuse the setting of cookies. In addition, cookies that have already been set can be deleted at any time via an internet browser or other software programs. This is possible in all common internet browsers. If the data subject deactivates the setting of cookies in the internet browser used, not all functions of our website may be fully available.
The use of cookies and similar technologies is based on Art. 6 (1) (a) GDPR and § 25 TDDDG. If you have given your consent, cookies will be set and your data will be processed. You can withdraw your consent at any time with effect for the future.
4. Collection of general data and information
The website of Amperecloud GmbH collects a range of general data and information when a data subject or an automated system accesses the website. This general data and information is stored in the server log files. The data that may be collected includes (1) the browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system reaches our website (the so-called referrer), (4) the subpages accessed, (5) the date and time of access to the website, (6) an Internet Protocol address (IP address), (7) the Internet service provider of the accessing system, and (8) any other similar data and information that can be used in the event of attacks on our IT systems.
Amperecloud GmbH does not draw any conclusions about the data subject from the use of these general data and information. Instead, this information is required in order (1) to deliver the content of our website correctly, (2) to optimise the content of our website and its advertising, (3) to ensure the long-term functionality of our IT systems and website technology, and (4) to provide law enforcement authorities with the information necessary for prosecution in the event of a cyberattack. Amperecloud GmbH therefore analyses anonymised data and information statistically in order to improve data protection and data security for companies.
5. Subscribing to our newsletters
On the website of Amperecloud GmbH, users have the option to subscribe to our company newsletter. The input form used for this purpose specifies which personal data is transmitted and when the newsletter is ordered from the controller.
Amperecloud GmbH regularly informs its customers and business partners about company offers via a newsletter. The company’s newsletter may only be received by a data subject if (1) the data subject has a valid email address and (2) the data subject has registered to receive the newsletter. For legal reasons, a confirmation email is sent using a double opt-in process to the email address that a data subject has first registered for newsletter delivery. This confirmation email is used to verify whether the owner of the email address, as the data subject, is authorized to receive the newsletter.
When you register for the newsletter, we also store the IP address assigned by the Internet Service Provider (ISP) and used by the data subject’s computer system at the time of registration, as well as the date and time of registration. Collecting this data is necessary to understand any potential misuse of a data subject’s email address at a later point in time and thus serves the purpose of providing legal protection for the controller responsible for the processing.
The personal data collected as part of the newsletter registration process is used solely for sending our newsletter. In addition, newsletter subscribers may be informed by email where this is necessary for operating the newsletter service or for the related registration, for example in the event of changes to the newsletter offering or to technical conditions. Personal data collected by the newsletter service is not passed on to third parties. The data subject may cancel their newsletter subscription at any time. Consent to the storage of personal data given by the data subject for the purpose of sending the newsletter can be withdrawn at any time. For this purpose, you will find a corresponding link in every newsletter. You can also unsubscribe from the newsletter at any time directly on the controller’s website or communicate your withdrawal to the controller in another way.
6. Newsletter tracking
The newsletter of Amperecloud GmbH contains what are known as tracking pixels. A tracking pixel is a small graphic embedded in emails that are sent in HTML format to enable the recording and analysis of log files. This allows statistical analysis of the success or failure of online marketing campaigns. Using the embedded tracking pixel, Amperecloud GmbH can see whether and when an email was opened by a data subject and which links in the email were accessed by them.
The personal data collected via the tracking pixels contained in the newsletters is stored and analysed by the controller in order to optimise the sending of the newsletter and to tailor the content of future newsletters even more closely to the interests of the data subject. This personal data is not passed on to third parties. Data subjects may revoke the separate declaration of consent given under the double opt-in procedure at any time. Once consent has been withdrawn, this personal data will be deleted by the controller. Amperecloud GmbH automatically treats an unsubscribe from the newsletter as a withdrawal of consent.
7. Contact options via the website
The website of Amperecloud GmbH contains information that enables quick electronic contact with our company and direct communication with us, including a general address for so‑called electronic mail (email address). If a data subject contacts the controller by email or via a contact form, the personal data transmitted by the data subject are stored automatically. Such personal data, which are transmitted voluntarily by a data subject to the controller, are stored for the purpose of processing the inquiry or contacting the data subject. These personal data are not disclosed to third parties.
8. Regular erasure and blocking of personal data
The controller processes and stores the data subject’s personal data only for the period necessary to achieve the purpose of storage, or for as long as this is permitted by the European legislator or other legislators in laws or regulations to which the controller is subject.
If the purpose for storing the data no longer applies, or if a retention period prescribed by European law or another applicable legal authority expires, the personal data will routinely be blocked or deleted in accordance with the legal requirements.
9. Rights of the data subject
a) Right to confirmation
Every data subject has the right granted by the European legislator to obtain from the controller confirmation as to whether or not personal data concerning them are being processed. If a data subject wishes to exercise this right to confirmation, they may contact a staff member of the controller at any time.
b) Right of access
Every data subject has the right, granted by the European legislator, to obtain from the controller, at any time and free of charge, information about their stored personal data and a copy of this information. In addition, the European directives and regulations grant the data subject access to the following information:
- the purposes of the processing;
- the categories of personal data concerned;
- the recipients or categories of recipients to whom the personal data have been or will be disclosed, in particular recipients in third countries or international organisations;
- where possible, the intended period for which the personal data will be stored, or, if this is not possible, the criteria used to determine that period;
- the existence of the right to request from the controller the rectification or erasure of personal data, or the restriction of the processing of the data subject’s personal data, or to object to such processing;
- the right to lodge a complaint with a supervisory authority;
- where the personal data are not collected from the data subject, all available information about their source;
- the existence of automated decision-making, including profiling, referred to in Article 22(1) and (4) of the GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject.
Furthermore, the data subject has the right to obtain information on whether personal data are being transferred to a third country or to an international organisation. In such cases, the data subject has the right to be informed about the appropriate safeguards relating to the transfer.
If a data subject wishes to exercise this right of access, they may contact an employee of the controller responsible for processing at any time.
c) Right to rectification
Every data subject has the right, granted by the European legislator, to obtain from the controller without undue delay the rectification of inaccurate personal data concerning them. Taking into account the purposes of the processing, the data subject has the right to have incomplete personal data completed, including by means of a supplementary statement.
If a data subject wishes to exercise this right to rectification, they may contact a member of the controller’s staff at any time.
d) Right to erasure (right to be forgotten)
Every data subject has the right, granted by the European legislator, to obtain from the controller the erasure of personal data concerning them without undue delay, and the controller is obliged to erase the personal data without undue delay where one of the following grounds applies, provided that processing is not required:
The personal data are no longer necessary for the purposes for which they were collected or otherwise processed.
The data subject withdraws the consent on which the processing is based in accordance with Article 6(1)(a) GDPR or Article 9(2)(a) GDPR, and there is no other legal basis for the processing.
The data subject objects to the processing pursuant to Article 21(1) GDPR and there are no compelling legitimate grounds for the processing, or the data subject objects to the processing pursuant to Article 21(2) GDPR.
The personal data have been processed unlawfully.
The personal data must be erased in order to comply with a legal obligation under Union or Member State law to which the controller is subject.
The personal data have been collected in relation to the offer of information society services referred to in Article 8(1) GDPR.
If one of the aforementioned reasons applies and a data subject wishes to request the deletion of the personal data stored by Amperecloud GmbH, they may contact an employee of the controller at any time. An employee of Amperecloud GmbH will ensure without delay that the deletion request is fulfilled immediately.
If the controller has made personal data public and is obliged under Article 17(1) to erase the personal data, the controller shall, taking account of available technology and the cost of implementation, take appropriate measures, including technical measures, to inform other controllers processing the personal data that the data subject has requested these controllers to erase any links to, or copies or replications of, those personal data, insofar as processing is not required. An employee of Amperecloud GmbH will, in individual cases, initiate the necessary measures.
e) Right to restriction of processing
Every data subject has the right granted by the European legislator to obtain from the controller a restriction of processing where one of the following conditions applies:
The data subject contests the accuracy of the personal data for a period that enables the controller to verify the accuracy of the personal data. The processing is unlawful and the data subject opposes the erasure of the personal data and instead requests the restriction of its use. The controller no longer needs the personal data for the purposes of the processing, but the data is required by the data subject for the establishment, exercise, or defence of legal claims. The data subject has objected to the processing pursuant to Article 21(1) of the GDPR, pending verification of whether the legitimate grounds of the controller override those of the data subject.
If one of the aforementioned conditions is met and a data subject wishes to request the restriction of the processing of personal data stored by Amperecloud GmbH, they may contact a member of staff of the controller at any time. The employee of Amperecloud GmbH will arrange for the restriction of the processing.
f) Right to data portability
Every data subject has the right, granted by the European legislator, to receive the personal data concerning them, which has been provided to a controller, in a structured, commonly used and machine-readable format. They have the right to transmit this data to another controller without hindrance from the controller to whom the personal data was provided, where the processing is based on consent pursuant to Article 6(1)(a) GDPR or Article 9(2)(a) GDPR, or on a contract pursuant to Article 6(1)(b) GDPR, and the processing is carried out by automated means, provided that the processing is not necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.
Furthermore, when exercising their right to data portability under Article 20(1) of the GDPR, the data subject has the right to have their personal data transmitted directly from one controller to another, where this is technically feasible and does not adversely affect the rights and freedoms of others.
To exercise the right to data portability, the data subject may contact any employee of Amperecloud GmbH at any time.
g) Right to object
Every data subject has the right, granted by the European legislator, to object at any time, on grounds relating to their particular situation, to the processing of personal data concerning them that is based on Article 6(1)(e) or (f) of the GDPR. This also applies to profiling based on these provisions.
In the event of an objection, Amperecloud GmbH will no longer process the personal data, unless we can demonstrate compelling legal grounds for the processing that override the interests, rights and freedoms of the data subject, or grounds for the establishment, exercise or defence of legal claims.
If Amperecloud GmbH processes personal data for direct marketing purposes, the data subject has the right to object at any time to the processing of their personal data for this marketing. This also applies to profiling, insofar as it is connected with such direct marketing. If the data subject objects to processing for direct marketing purposes by Amperecloud GmbH, Amperecloud GmbH will no longer process the personal data for these purposes.
Furthermore, the data subject has the right, on grounds relating to their particular situation, to object to the processing of their personal data by Amperecloud GmbH for scientific or historical research purposes or for statistical purposes in accordance with Article 89(1) GDPR, unless the processing is necessary for the performance of a task carried out for reasons of public interest.
To exercise the right to object, the data subject may contact any employee of Amperecloud GmbH. In addition, when using services of the information society and notwithstanding Directive 2002/58/EC, the data subject is free to exercise their right to object by automated means using technical specifications.
h) Automated individual decision-making, including profiling
Every data subject has the right, granted by the European legislator, not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them, as long as the decision (1) is not necessary for entering into or performing a contract between the data subject and a controller, or (2) is not authorised by Union or Member State law to which the controller is subject and which also lays down suitable measures to safeguard the rights and freedoms and the legitimate interests of the data subject, or (3) is not based on the data subject’s explicit consent.
If the decision is (1) necessary for entering into or performing a contract between the data subject and a controller, or (2) based on the explicit consent of the data subject, Amperecloud GmbH will take appropriate measures to protect the rights, freedoms, and legitimate interests of the data subject, including at least the right to obtain human intervention on the part of the controller, to express their point of view, and to contest the decision.
If the data subject wishes to exercise their rights relating to automated individual decision-making, they may contact an employee of Amperecloud GmbH at any time.
i) Right to withdraw consent to data protection
Every data subject has the right, granted by the European legislator, to withdraw their consent to the processing of their personal data at any time.
If the data subject wishes to exercise the right to withdraw consent, they may contact an employee of Amperecloud GmbH at any time.
10. Data protection provisions on the use of Google Analytics (with anonymization function)
On this website, the controller has integrated the Google Analytics component (with the anonymization function). Google Analytics is a web analytics service. Web analytics is the collection, gathering, and analysis of data about the behavior of visitors to websites. A web analytics service collects, among other things, data about the website from which a person has come (the so‑called referrer), which subpages were visited, or how often and for how long a subpage was viewed. Web analytics is mainly used to optimize a website and to carry out a cost-benefit analysis of online advertising.
The legal basis for the use of Google Analytics is your consent in accordance with Art. 6 (1) (a) GDPR and Section 25 (1) TDDDG.
The operator of the Google Analytics component is Google Ireland Limited, Gordon House, Barrow Street, Dublin, D04 E5W5, Ireland.
For web analytics via Google Analytics, the controller uses the application “_gat._anonymizeIp”. This application causes Google to shorten and anonymize the IP address of the data subject’s internet connection when you access our websites from a member state of the European Union or from another contracting state of the Agreement on the European Economic Area.
The purpose of the Google Analytics component is to analyze the traffic on our website. Google uses the collected data and information, among other things, to evaluate how our website is used and to provide online reports that show activities on our websites, as well as to deliver other services related to the use of our website for us.
Google Analytics places a cookie on the information system of the data subject. The definition of cookies is explained above. By setting this cookie, Google is able to analyse how our website is used. Every time one of the individual pages of this website operated by the controller, on which a Google Analytics component is integrated, is accessed, the internet browser on the information technology system of the data subject automatically transmits data about the Google Analytics component to Google for the purposes of online advertising and commission billing. In the course of this technical process, Google obtains knowledge of personal data, such as the IP address of the data subject, which Google uses, among other things, to determine the origin of visitors and clicks and subsequently to prepare commission statements.
The cookie is used to store personal data such as the time of access, the location from which access took place, and the frequency of visits to our website by the data subject. Each time our website is visited, this personal data, including the IP address of the internet connection used by the data subject, is transmitted to Google in the United States of America. This personal data is stored by Google in the United States of America. As part of the technical process, Google may pass this personal data on to third parties.
As described above, the data subject can prevent cookies from being set via our website at any time by adjusting the settings of the web browser used, and can thus permanently refuse the use of cookies. Such an adjustment of the internet browser used would also prevent Google Analytics from placing a cookie on the data subject’s information system. In addition, cookies already set by Google Analytics can be deleted at any time via a web browser or other software programs.
In addition, the data subject has the option to object to the collection of data generated by Google Analytics in connection with the use of this website, as well as to the processing of this data by Google and the option to opt out. To do this, the data subject must download and install a browser add-on from the following link https://tools.google.com/dlpage/gaoptout. This browser add-on informs Google Analytics via a JavaScript command that data and information about visits to websites may not be transmitted to Google Analytics. Installing the browser add-on is considered an objection by Google. If the data subject’s IT system is later deleted, formatted, or reinstalled, the data subject must reinstall the browser add-on to deactivate Google Analytics. If the browser add-on has been uninstalled or deactivated by the data subject or another person within their area of responsibility, it is possible to reinstall or reactivate the browser add-on.
Further information and the applicable data protection provisions of Google can be found at https://www.google.com/intl/en/policies/privacy/and at http://www.google.com/analytics/terms/us.html. Google Analytics is explained in more detail at the following link https://www.google.com/analytics/.
11. Data protection provisions on the use of Google AdWords
The controller has integrated Google AdWords on this website. Google AdWords is an online advertising service that enables advertisers to place ads in Google’s search engine results and across the Google advertising network. Google AdWords allows an advertiser to define specific keywords so that an ad is only displayed in Google’s search results when the user uses the search engine to obtain a search result relevant to those keywords. In the Google advertising network, ads are distributed across relevant websites using an automatic algorithm that takes the previously defined keywords into account.
The use of Google AdWords and the placement of conversion cookies is based on your consent in accordance with Art. 6 (1) (a) GDPR and Section 25 (1) TDDDG.
The operating company for Google AdWords is Google Ireland Limited, Gordon House, Barrow Street, Dublin, D04 E5W5, Ireland.
The purpose of Google AdWords is to promote our website by placing relevant advertising on third‑party websites and in the search results of the Google search engine, as well as by displaying third‑party advertising on our website.
If a data subject reaches our website via a Google ad, Google places a conversion cookie on the data subject’s information system. The definition of cookies is explained above. A conversion cookie expires after 30 days and is not used to identify the data subject. If the cookie has not yet expired, the conversion cookie is used to check whether certain subpages on our website have been accessed, for example the shopping cart of an online shop system. The conversion cookie enables both Google and the controller to understand whether a person who has reached our website via an AdWords ad generates sales, i.e. has completed or cancelled a purchase.
The data and information collected through the use of the conversion cookie are used by Google to compile visitor statistics for our website. These visitor statistics are used to determine the total number of users served via AdWords ads, to assess the success or failure of each AdWords ad, and to optimise our AdWords ads in the future. Neither our company nor other Google AdWords customers receive information from Google that would allow the identification of the data subject.
The conversion cookie stores personal data, for example the web pages visited by the data subject. Every time our website is visited, personal data, including the IP address of the internet connection used by the data subject, is transmitted to Google in the United States of America. This personal data is stored by Google in the United States of America. As part of this technical process, Google may pass this personal data on to third parties.
The data subject can prevent cookies from being set by our website at any time, as described above, by adjusting the settings of the internet browser used, and can thus permanently prevent cookies from being stored. Such a setting of the internet browser used would also prevent Google from placing a conversion cookie on the data subject’s information system. In addition, a cookie set by Google AdWords can be deleted at any time via the internet browser or other software programs.
The data subject has the option to object to interest-based advertising by Google. To do so, the data subject must access the link www.google.de/settings/ads from each browser used and configure the desired settings.
Further information and the applicable data protection provisions of Google can be found at https://www.google.com/intl/en/policies/privacy/.
12. Data protection provisions on the use of Jetpack for WordPress
This website has integrated the Jetpack plugin. Jetpack is a WordPress plugin that provides the operator of a WordPress-based website with additional features. Among other things, Jetpack gives the site operator an overview of the website’s visitors. By displaying related posts and publications, and by allowing content to be shared on the site, it can also help increase visitor numbers. In addition, Jetpack includes security features that better protect a Jetpack user’s site against brute-force attacks. Jetpack also optimizes and speeds up image loading on the website.
Jetpack sets cookies on the basis of your consent in accordance with Art. 6(1)(a) GDPR and Section 25(1) TDDDG.
The operating company of Jetpack plug-ins for WordPress is Aut O’Mattic A8C Ireland Ltd., Business Centre, No.1 Lower Mayor Street, International Financial Services Centre, Dublin 1, Ireland.
Jetpack places a cookie on the information technology system used by the data subject. The definition of cookies is explained above. Every time one of the individual pages of this website operated by the controller and containing a Jetpack component is accessed, the internet browser on the information technology system of the data subject is automatically prompted to transmit data about the Jetpack component to Automattic for analysis purposes. As part of this technical process, Automattic receives data that can be used to create an overview of visits to the website. The data obtained in this way is used to analyze the behavior of the data subject who accesses the controller’s website, with the aim of optimizing the website. The data collected by the Jetpack component is not used to identify the data subject without the prior explicit consent of the data subject. The data also becomes known to Quantcast. Quantcast uses the data for the same purposes as Automattic.
As described above, the data subject can prevent cookies from being set via our website at any time by adjusting the settings of the web browser used, and thus permanently prevent the placement of cookies. Such an adjustment of the internet browser used would also prevent Automattic/Quantcast from placing a cookie on the data subject’s information system. In addition, cookies already used by Automattic/Quantcast can be deleted at any time via a web browser or other software programs.
Furthermore, the data subject has the option to object to the collection of data related to the use of this website that is generated by the Jetpack cookie, and to the processing of this data by Automattic/Quantcast, and to prevent this. For this purpose, the data subject must go to the link https://www.quantcast.com/opt-out/ and click the “Opt-out” button, which sets an opt-out cookie. The opt-out cookie set for this purpose is stored on the information technology system used by the data subject. If the cookies on the data subject’s system are deleted, the data subject must access the link again and set a new opt-out cookie.
However, by setting the opt-out cookie, it is possible that the controller’s websites may no longer be fully usable for the data subject.
The applicable data protection provisions of Automattic are available at https://automattic.com/privacy/. The applicable data protection provisions of Quantcast are available at https://www.quantcast.com/privacy/.
13. Data protection provisions for the use of LinkedIn
The controller has integrated components of LinkedIn Corporation on this website. LinkedIn is a web-based social network that enables users with existing business contacts to connect and establish new business relationships. More than 400 million registered users in over 200 countries use LinkedIn. This makes LinkedIn currently the largest platform for business contacts and one of the most visited websites in the world.
The operating company of LinkedIn is LinkedIn Corporation, 2029 Stierlin Court, Mountain View, CA 94043, United States. For data protection matters outside the UNITED STATES, LinkedIn Ireland, Privacy Policy Issues, Wilton Plaza, Wilton Place, Dublin 2, Ireland, is responsible.
Every time one of the individual pages of this website operated by the controller, on which a LinkedIn component (LinkedIn plugin) has been integrated, is accessed, the internet browser on the data subject’s system is automatically prompted by LinkedIn to download a display of the corresponding LinkedIn component. You can find more information about the LinkedIn plugin at https://developer.linkedin.com/plugins In the course of this technical process, LinkedIn learns which specific subpage of our website the data subject has visited.
If the data subject is logged in to LinkedIn at the same time, LinkedIn recognizes, each time our website is accessed by the data subject – for the entire duration of their visit to our website – which specific subpage of our site they have visited. This information is collected via the LinkedIn component and linked to the respective LinkedIn account of the data subject. If the data subject clicks one of the LinkedIn buttons integrated into our website, LinkedIn assigns this information to the personal LinkedIn user account of the data subject and stores the personal data.
Via the LinkedIn component, LinkedIn receives the information that the data subject has visited our website, provided the data subject is logged in to LinkedIn at the time our website is accessed. This happens regardless of whether the person clicks the LinkedIn button or not. If the data subject does not want such information to be transmitted to LinkedIn, they can prevent this by logging out of their LinkedIn account before accessing our website.
LinkedIn offers at https://www.linkedin.com/psettings/guest-controls the option to unsubscribe from email messages, SMS messages, and targeted ads, as well as to manage ad settings. LinkedIn also uses affiliates such as Eire, Google Analytics, BlueKai, DoubleClick, Nielsen, Comscore, Eloqua, and Lotame. You can refuse the placement of such cookies at https://www.linkedin.com/legal/cookie-policy. The applicable privacy policy for LinkedIn is available at https://www.linkedin.com/legal/privacy-policy. The LinkedIn Cookie Policy is available at https://www.linkedin.com/legal/cookie-policy.
14. Data protection provisions for the use of Xing
This website uses integrated components from XING. XING is an internet-based social network that enables users to connect with existing business contacts and establish new ones. Individual users can create a personal profile on XING. Companies can, for example, create company profiles or post jobs on XING.
The operating company of XING is XING SE, Dammtorstraße 30, 20354 Hamburg, Germany.
Every time one of the individual pages of this website operated by the controller is accessed and a XING component (XING plugin) has been integrated on it, the internet browser on the data subject’s information system is automatically prompted to download a display of the corresponding XING component from XING. You can find more information about the XING plugin at https://dev.xing.com/plugins In the course of this technical process, XING learns which specific subpage of our website was visited by the data subject.
If the data subject is logged in to XING at the same time, XING recognizes, on each visit to our website by the data subject – for the entire duration of their stay on our website – which specific subpage of our website the data subject has accessed. This information is collected via the XING component and linked to the respective XING account of the data subject. If the data subject clicks the XING button integrated into our website, for example the “Share” button, XING assigns this information to the personal XING user account of the data subject and stores the personal data.
Via the XING component, XING receives the information that the data subject has visited our website, provided the data subject is logged in to XING at the time our website is accessed. This happens regardless of whether the person clicks on the XING component or not. If the data subject does not want such information to be transmitted to XING, they can prevent this by logging out of their XING account before accessing our website.
Information about the collection, processing and use of personal data by XING can be found in the data protection provisions published by XING, available at https://www.xing.com/privacy. In addition, XING has published data protection information for the XING share button at https://www.xing.com/app/share?op=data_protection.
15. Legal basis for processing
Art. 6(1)(a) GDPR serves as the legal basis for processing operations for which we obtain consent for a specific processing purpose. If the processing of personal data is necessary for the performance of a contract to which the data subject is party, as is the case, for example, when processing is required for the delivery of goods or the provision of another service, the processing is based on Article 6(1)(b) GDPR. The same applies to processing operations that are necessary to carry out pre-contractual measures, for example in the case of enquiries about our products or services.
If our company is subject to a legal obligation that requires the processing of personal data, for example to fulfil tax obligations, the processing is based on Art. 6(1)(c) GDPR. In rare cases, the processing of personal data may be necessary to protect the vital interests of the data subject or another natural person. This is the case, for example, if a visitor is injured on our premises and their name, age, health insurance data or other essential information must be passed on to a doctor, a hospital or another third party. In that case, the processing would be based on Art. 6(1)(d) GDPR.
Finally, processing operations could be based on Article 6(1)(f) GDPR. This legal basis is used for processing operations that are not covered by any of the aforementioned legal grounds, where processing is necessary for the purposes of the legitimate interests pursued by our company or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require the protection of personal data. Such processing operations are particularly permissible because they have been expressly mentioned by the European legislator. The legislator considered that a legitimate interest could be assumed if the data subject is a customer of the controller (Recital 47, sentence 2 GDPR).
16. The legitimate interests pursued by the controller or by a third party
If the processing of personal data is based on Article 6(1)(f) GDPR, our legitimate interest lies in conducting our business activities for the benefit of all our employees and shareholders.
17. Period for which the personal data will be stored
The applicable statutory retention period is decisive for how long personal data is stored. After this period expires, the relevant data is routinely deleted, provided it is no longer required for the performance of the contract or the initiation of a contract.
18. Provision of personal data as a legal or contractual requirement
Requirement for concluding a contract; obligation of the data subject to provide the personal data; possible consequences of not providing this data
We point out that providing personal data is partly required by law (e.g. tax regulations) and may also result from contractual obligations (e.g. information about the contracting party). In some cases, it may be necessary to conclude a contract under which the data subject provides us with personal data that we then have to process. For example, the data subject is obliged to provide us with personal data if our company concludes a contract with them. If the personal data is not provided, the contract with the data subject cannot be concluded. Before the data subject provides personal data, they must contact a member of staff. The staff member will explain to the data subject whether the provision of personal data is required by law or by contract, or is necessary for concluding the contract, whether there is an obligation to provide the personal data, and what the consequences of not providing the personal data would be.
19. Existence of automated decision-making
As a responsible company, we do not use automated decision-making or profiling.
This privacy policy was created using the Privacy Policy Generator from DGD – Your External DPO, which was developed in cooperation with German lawyers from WILDE BEUGER SOLMECKE, Cologne.