Privacy Policy

Thank you for your interest in our company. Data protection is of a particularly high priority for the management of Converia GmbH. The use of the Converia GmbH website is generally possible without any indication of personal data. However, if a data subject wishes to use special services via our website, the processing of personal data could become necessary. If the processing of personal data is necessary and there is no statutory basis for such processing, we generally obtain the consent of the data subject.

The processing of personal data, such as the name, address, email address, or telephone number of a data subject, is always in line with the General Data Protection Regulation and in accordance with the country-specific data protection regulations applicable to Converia GmbH. By means of this privacy policy, our company would like to inform visitors to our website about the nature, scope, and purpose of the personal data we collect, use, and process. Furthermore, data subjects are informed of their rights by means of this privacy policy.

As the controller, Converia GmbH has implemented numerous technical and organizational measures to ensure the most complete protection of personal data processed through this website. However, internet-based data transmissions may in principle have security gaps, so that absolute protection cannot be guaranteed. For this reason, every data subject is free to transfer personal data to us via alternative means, such as by telephone.

The Converia GmbH privacy policy is based on the terminology used by the European legislator for the adoption of the General Data Protection Regulation (GDPR). Our privacy policy is intended to be easily readable and understandable for the general public as well as for our customers and business partners.

Name and address of the controller

The controller for the purposes of the General Data Protection Regulation (GDPR), other data protection laws applicable in Member States of the European Union, and other provisions related to data protection is:

Converia GmbH
Kaufstraße 2–4
99423 Weimar
Germany

Phone: +49 3643/8118070
Email: info@converia.de
Website: www.converia.de

If you have any questions regarding data protection, you can contact our data protection team at any time: datenschutz@converia.de

Cookies

The Converia GmbH websites use cookies. Cookies are text files that are placed and stored on a computer system via an internet browser.

Numerous websites and servers use cookies. Many cookies contain a so-called cookie ID. A cookie ID is a unique identifier for the cookie. It consists of a string of characters through which websites and servers can be assigned to the specific internet browser in which the cookie was stored. This allows the visited websites and servers to distinguish the individual browser of the data subject from other internet browsers that contain other cookies. A specific internet browser can be recognized and identified via the unique cookie ID.

By using cookies, Converia GmbH can provide users of this website with more user-friendly services that would not be possible without the setting of cookies.

Cookies allow information and offers on our website to be optimized for the user. As mentioned, cookies enable us to recognize our website users. The purpose of this recognition is to make it easier for users to use our website. For example, a user of a website that uses cookies does not have to re-enter their access data every time they visit the website, because this is handled by the website and the cookie stored on the user's computer system. Another example is the shopping cart cookie in an online shop. The online shop uses a cookie to remember the items a customer has placed in the virtual shopping cart.

The data subject can prevent the setting of cookies by our website at any time by means of a corresponding setting in the internet browser used and thus permanently object to the setting of cookies. Furthermore, cookies that have already been set can be deleted at any time via an internet browser or other software programs. This is possible in all common internet browsers. If the data subject deactivates the setting of cookies in the internet browser used, not all functions of our website may be fully usable.

Collection of general data and information

The Converia GmbH website collects a series of general data and information each time the website is accessed by a data subject or an automated system. This general data and information is stored in the server's log files. The data collected may include (1) the browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system reaches our website (so-called referrers), (4) the sub-websites accessed via an accessing system on our website, (5) the date and time of access to the website, (6) an Internet Protocol address (IP address), (7) the internet service provider of the accessing system, and (8) other similar data and information that serve to avert danger in the event of attacks on our information technology systems.

When using this general data and information, Converia GmbH does not draw any conclusions about the data subject. Rather, this information is required to (1) deliver the content of our website correctly, (2) optimize the content of our website and the advertising for it, (3) ensure the long-term functionality of our information technology systems and the technology of our website, and (4) provide law enforcement authorities with the information necessary for prosecution in the event of a cyberattack. This anonymously collected data and information is therefore evaluated by Converia GmbH both statistically and with the aim of increasing data protection and data security in our company, in order to ultimately ensure an optimal level of protection for the personal data we process. The anonymous data in the server log files is stored separately from all personal data provided by a data subject.

Contact options via the website

Due to legal requirements, the Converia GmbH website contains information that enables quick electronic contact with our company and direct communication with us, which also includes a general address for so-called electronic mail (email address). If a data subject contacts the controller via email or a contact form, the personal data transmitted by the data subject is automatically stored. Such personal data transmitted on a voluntary basis by a data subject to the controller is stored for the purpose of processing or contacting the data subject.

To process and respond to your inquiries and messages as quickly as possible, we have connected our contact form to our customer relationship management tool ("CRM tool"), Pipedrive.

We use the CRM system Pipedrive, provided by Pipedrive OÜ, Paldiski mnt 80, Tallinn, 10617, Estonia, based on our legitimate interests in accordance with Art. 6(1)(f) GDPR. Our interests are the acquisition of new customers and providing the best possible support to existing customers. The data submitted when filling out the form is processed within the Pipedrive system.

We also use Pipedrive for our online marketing activities. Specifically, this means:

  • Contact management (user segmentation)
  • Email marketing (newsletter)

Every newsletter contains an unsubscribe link, which you can use to withdraw your consent to receive the newsletter at any time. In the event of a withdrawal, we will no longer use any personal data processed in connection with the distribution of the newsletter for advertising purposes.

Routine erasure and blocking of personal data

The data controller shall process and store the personal data of the data subject only for the period necessary to achieve the purpose of storage, or as provided for by the European legislator or other legislators in laws or regulations to which the controller is subject.

If the storage purpose ceases to apply or if a storage period prescribed by the European legislator or another competent legislator expires, the personal data will be routinely blocked or erased in accordance with legal requirements.

Rights of the data subject

a) Right of confirmation

Every data subject has the right granted by the European legislator to obtain from the controller confirmation as to whether or not personal data concerning them are being processed. If a data subject wishes to exercise this right of confirmation, they may contact an employee of the data controller at any time.

b) Right of access

Every data subject affected by the processing of personal data has the right granted by the European legislator to obtain from the controller, at any time and free of charge, information about the personal data stored about them and a copy of this information. Furthermore, the European legislator has granted the data subject access to the following information:

  • the purposes of the processing
  • the categories of personal data concerned
  • the recipients or categories of recipients to whom the personal data have been or will be disclosed, in particular recipients in third countries or international organizations
  • where possible, the envisaged period for which the personal data will be stored, or, if not possible, the criteria used to determine that period
  • the existence of the right to request rectification or erasure of personal data or restriction of processing of personal data concerning the data subject or to object to such processing
  • the right to lodge a complaint with a supervisory authority
  • where the personal data are not collected from the data subject: any available information as to their source
  • the existence of automated decision-making, including profiling, referred to in Article 22(1) and (4) of the GDPR and, at least in these cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject

Furthermore, the data subject has the right to obtain information as to whether personal data has been transferred to a third country or to an international organization. Where this is the case, the data subject also has the right to obtain information regarding the appropriate safeguards relating to the transfer.

If a data subject wishes to exercise this right of access, they may contact an employee of the data controller at any time.

c) Right to rectification

Every data subject affected by the processing of personal data has the right granted by the European legislator to obtain the immediate rectification of inaccurate personal data concerning them. Furthermore, taking into account the purposes of the processing, the data subject has the right to have incomplete personal data completed, including by means of providing a supplementary statement.

If a data subject wishes to exercise this right to rectification, they may contact an employee of the data controller at any time.

d) Right to erasure (right to be forgotten)

Every data subject affected by the processing of personal data has the right granted by the European legislator to obtain from the controller the erasure of personal data concerning them without undue delay, provided that one of the following reasons applies and as long as the processing is not necessary:

  • The personal data have been collected or otherwise processed for purposes for which they are no longer necessary.
  • The data subject withdraws consent on which the processing is based according to Art. 6(1)(a) GDPR or Art. 9(2)(a) GDPR, and there is no other legal ground for the processing.
  • The data subject objects to the processing pursuant to Art. 21(1) GDPR and there are no overriding legitimate grounds for the processing, or the data subject objects to the processing pursuant to Art. 21(2) GDPR.
  • The personal data have been unlawfully processed.
  • The personal data must be erased for compliance with a legal obligation in Union or Member State law to which the controller is subject.
  • The personal data have been collected in relation to the offer of information society services referred to in Art. 8(1) GDPR.

If one of the aforementioned reasons applies and a data subject wishes to request the erasure of personal data stored by Converia GmbH, they may contact an employee of the controller at any time. The Converia GmbH employee will ensure that the request for erasure is complied with immediately.

If Converia GmbH has made personal data public and our company as the controller is obliged pursuant to Art. 17(1) GDPR to erase the personal data, Converia GmbH, taking into account available technology and the cost of implementation, shall take reasonable steps, including technical measures, to inform other controllers processing the published personal data that the data subject has requested the erasure by such controllers of any links to, or copy or replication of, those personal data, as far as processing is not required. The Converia GmbH employee will arrange the necessary measures in each individual case.

e) Right to restriction of processing

Every data subject affected by the processing of personal data has the right granted by the European legislator to obtain from the controller restriction of processing where one of the following applies:

The accuracy of the personal data is contested by the data subject for a period enabling the controller to verify the accuracy of the personal data.

The processing is unlawful, the data subject opposes the erasure of the personal data, and requests the restriction of their use instead.

The controller no longer needs the personal data for the purposes of processing, but the data subject requires them for the establishment, exercise, or defense of legal claims.

The data subject has objected to the processing pursuant to Art. 21(1) GDPR, and it is not yet certain whether the legitimate grounds of the controller override those of the data subject.

If one of the aforementioned conditions is met and a data subject wishes to request the restriction of personal data stored by Converia GmbH, they may contact an employee of the controller at any time. The Converia GmbH employee will arrange for the restriction of processing.

f) Right to data portability

Every data subject affected by the processing of personal data has the right granted by the European legislator to receive the personal data concerning them, which they have provided to a controller, in a structured, commonly used, and machine-readable format. They also have the right to transmit those data to another controller without hindrance from the controller to which the personal data have been provided, provided that the processing is based on consent pursuant to Art. 6(1)(a) GDPR or Art. 9(2)(a) GDPR, or on a contract pursuant to Art. 6(1)(b) GDPR, and the processing is carried out by automated means, provided that the processing is not necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.

Furthermore, when exercising their right to data portability pursuant to Art. 20(1) GDPR, the data subject has the right to have the personal data transmitted directly from one controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.

To exercise the right to data portability, the data subject may contact an employee of Converia GmbH at any time.

g) Right to object

Every person affected by the processing of personal data has the right granted by the European legislator to object at any time, on grounds relating to their particular situation, to the processing of personal data concerning them which is based on Art. 6(1)(e) or (f) GDPR. This also applies to profiling based on these provisions.

In the event of an objection, Converia GmbH will no longer process the personal data unless we can demonstrate compelling legitimate grounds for the processing which override the interests, rights, and freedoms of the data subject, or for the establishment, exercise, or defense of legal claims.

If Converia GmbH processes personal data for direct marketing purposes, the data subject has the right to object at any time to the processing of personal data for the purpose of such marketing. This also applies to profiling to the extent that it is related to such direct marketing. If the data subject objects to Converia GmbH to processing for direct marketing purposes, Converia GmbH will no longer process the personal data for these purposes.

Furthermore, the data subject has the right to object, on grounds relating to their particular situation, to the processing of personal data concerning them which is carried out by Converia GmbH for scientific or historical research purposes or for statistical purposes pursuant to Art. 89(1) GDPR, unless such processing is necessary for the performance of a task carried out for reasons of public interest.

To exercise the right to object, the data subject may contact any employee of Converia GmbH or another staff member directly. In the context of the use of information society services, and notwithstanding Directive 2002/58/EC, the data subject is also free to exercise their right to object by automated means using technical specifications.

h) Automated individual decision-making, including profiling

Every person affected by the processing of personal data has the right granted by the European legislator not to be subject to a decision based solely on automated processing—including profiling—which produces legal effects concerning them or similarly significantly affects them, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the data subject and the controller, or (2) is permitted by Union or Member State law to which the controller is subject and these legal provisions contain appropriate measures to safeguard the rights and freedoms as well as the legitimate interests of the data subject, or (3) is made with the data subject's explicit consent.

If the decision (1) is necessary for the conclusion or performance of a contract between the data subject and the controller, or (2) is made with the data subject's explicit consent, Converia GmbH will take appropriate measures to safeguard the rights and freedoms as well as the legitimate interests of the data subject, which include at least the right to obtain human intervention on the part of the controller, to express their point of view, and to contest the decision.

If the data subject wishes to exercise rights regarding automated decision-making, they may contact an employee of the controller at any time.

i) Right to withdraw consent under data protection law

Every person affected by the processing of personal data has the right granted by the European legislator to withdraw consent to the processing of personal data at any time.

If the data subject wishes to exercise their right to withdraw consent, they may contact an employee of the controller at any time.

Data protection for applications and the application process

The controller collects and processes the personal data of applicants for the purpose of managing the application process. Processing may also be carried out electronically. This is particularly the case if an applicant submits relevant application documents electronically, for example by email or via a web form on the website, to the controller. If the controller concludes an employment contract with an applicant, the submitted data will be stored for the purpose of managing the employment relationship in compliance with legal requirements. If no employment contract is concluded with the applicant by the controller, the application documents will be automatically deleted two months after the rejection decision is announced, provided that no other legitimate interests of the controller prevent such deletion. Other legitimate interests in this sense include, for example, a burden of proof in proceedings under the General Equal Treatment Act (AGG).

Webflow

We host our website with Webflow. The provider is Webflow, Inc., 398 11th Street, 2nd Floor, San Francisco, CA 94103, USA (hereinafter: Webflow). When you visit our website, Webflow collects various log files, including your IP addresses.

Webflow is a tool for creating and hosting websites. Webflow stores cookies or other recognition technologies that are necessary for displaying the site, providing certain website functions, and ensuring security (necessary cookies).

For details, please refer to the Webflow privacy policy: EU & Swiss Privacy Policy | Webflow 32.

The use of Webflow is based on Art. 6(1)(f) GDPR. We have a legitimate interest in ensuring the most reliable presentation of our website possible. Where corresponding consent has been requested, processing is carried out exclusively on the basis of Art. 6(1)(a) GDPR and § 25(1) TTDSG, insofar as the consent includes the storage of cookies or access to information on the user's terminal device (e.g., device fingerprinting) within the meaning of the TTDSG. Consent can be revoked at any time.

Data transfer to the USA is based on the EU Commission's Standard Contractual Clauses. Details can be found here: EU & Swiss Privacy Policy | Webflow 32.

Data processing

We have entered into a data processing agreement (DPA) with the aforementioned provider. This is a contract required by data protection law, which ensures that the provider processes the personal data of our website visitors only according to our instructions and in compliance with the GDPR.

Data protection provisions regarding the use of Intercom

As a support system, we use the services of Intercom R&D Unlimited Company (hereinafter "Intercom"), based in Ireland.

We use Intercom to effectively process and respond to support requests from customers and third parties. We have entered into a data processing agreement with Intercom that meets the requirements of Art. 28 GDPR. We have established contractual arrangements with Intercom that ensure data is processed in data centers within the European Union. In principle, no processing in third countries takes place.

Intercom is a company with a parent company in the USA (Intercom, Inc.). In support cases, it may be necessary for Intercom USA employees to have access to personal data. An adequate level of data protection is also ensured in these cases through the conclusion of EU Standard Contractual Clauses. Furthermore, Intercom, Inc. is also certified under the EU-U.S. Data Privacy Framework.

Data protection provisions regarding the use of Google Analytics (with anonymization function)

The controller has integrated the Google Analytics component (with anonymization function) on this website. Google Analytics is a web analysis service. Web analysis is the collection, gathering, and evaluation of data regarding the behavior of website visitors. A web analysis service collects, among other things, data on which website a data subject came from (so-called referrers), which subpages of the website were accessed, or how often and for what duration a subpage was viewed. Web analysis is primarily used for the optimization of a website and for the cost-benefit analysis of internet advertising.

The operating company of the Google Analytics component is Google Ireland Limited, based in Ireland. With regard to any potential transfers to the US parent company (Google LLC), Google Ireland Limited ensures an adequate level of data protection by using the so-called EU Standard Contractual Clauses. Additionally, Google's US parent company is certified under the EU-U.S. Data Privacy Framework.

For web analysis via Google Analytics, the controller uses the suffix "_gat._anonymizeIp". By means of this suffix, the IP address of the data subject's internet connection is shortened and anonymized by Google if access to our websites occurs from a member state of the European Union or another contracting state to the Agreement on the European Economic Area.

The purpose of the Google Analytics component is to analyze visitor traffic on our website. Google uses the data and information obtained, among other things, to evaluate the use of our website, to compile online reports for us that show the activities on our websites, and to provide other services related to the use of our website.

Google Analytics sets a cookie on the data subject's information technology system. What cookies are has already been explained above. By setting the cookie, Google is enabled to analyze the use of our website. Each time one of the individual pages of this website, which is operated by the controller and on which a Google Analytics component has been integrated, is accessed, the internet browser on the data subject's information technology system is automatically prompted by the respective Google Analytics component to transmit data to Google for the purpose of online analysis. As part of this technical process, Google gains knowledge of personal data, such as the data subject's IP address, which serves Google, among other things, to track the origin of visitors and clicks and subsequently to enable commission settlements.

The cookie stores personal information, such as access time, the location from which access originated, and the frequency of the data subject's visits to our website. During each visit to our websites, this personal data, including the IP address of the internet connection used by the data subject, is transmitted to Google in the United States of America. This personal data is stored by Google in the United States of America. Google may share this personal data collected through the technical process with third parties.

As previously described, the data subject can prevent the setting of cookies by our website at any time by adjusting the settings of their internet browser, thereby permanently objecting to the setting of cookies. Such a setting in the internet browser used would also prevent Google from setting a cookie on the data subject's information technology system. Additionally, a cookie already set by Google Analytics can be deleted at any time via the internet browser or other software programs.

Furthermore, the data subject has the option to object to and prevent the collection of data generated by Google Analytics regarding the use of this website, as well as the processing of this data by Google. To do this, the data subject must download and install a browser add-on from the link https://tools.google.com/dlpage/gaoptout. This browser add-on informs Google Analytics via JavaScript that no data or information about website visits may be transmitted to Google Analytics. Google considers the installation of the browser add-on as an objection. If the data subject's information technology system is later deleted, formatted, or reinstalled, the data subject must reinstall the browser add-on to disable Google Analytics. If the browser add-on is uninstalled or disabled by the data subject or any other person within their control, there is the option to reinstall or reactivate the browser add-on.

Further information and Google's applicable data protection provisions can be found at https://www.google.de/intl/de/policies/privacy/ and http://www.google.com/analytics/terms/de.html. Google Analytics is explained in more detail at this link: https://www.google.com/intl/de_de/analytics/.

Data protection provisions regarding the use of Google Remarketing

The controller has integrated Google Remarketing services on this website. Google Remarketing is a feature of Google Ads that allows a company to display advertisements to internet users who have previously visited the company's website. The integration of Google Remarketing therefore enables a company to create user-related advertising and subsequently display interest-based ads to the internet user.

The operating company for Google Remarketing services is Google Ireland Limited, based in Ireland.

The purpose of Google Remarketing is to display interest-based advertising. Google Remarketing allows us to display advertisements via the Google advertising network or to have them displayed on other websites that are tailored to the individual needs and interests of internet users.

Google Remarketing sets a cookie on the data subject's information technology system. What cookies are has already been explained above. By setting the cookie, Google is enabled to recognize the visitor to our website when they subsequently visit websites that are also members of the Google advertising network. With each visit to a website on which the Google Remarketing service has been integrated, the data subject's internet browser automatically identifies itself to Google. As part of this technical process, Google gains knowledge of personal data, such as the user's IP address or browsing behavior, which Google uses, among other things, to display interest-based advertising.

Personal information, such as the websites visited by the data subject, is stored by means of the cookie. Consequently, every time you visit our websites, personal data, including the IP address of the internet connection used by the data subject, is transmitted to Google in the United States of America. This personal data is stored by Google in the United States of America. Google may pass this personal data collected through the technical process on to third parties.

As described above, the data subject can prevent the setting of cookies by our website at any time by means of a corresponding setting in the internet browser used, thereby permanently objecting to the setting of cookies. Such a setting in the internet browser used would also prevent Google from setting a cookie on the data subject's information technology system. In addition, a cookie already set by Google Analytics can be deleted at any time via the internet browser or other software programs.

Furthermore, the data subject has the option to object to interest-based advertising by Google. To do this, the data subject must visit the link www.google.de/settings/ads from each of the internet browsers they use and make the desired settings there.

Further information and Google's applicable privacy policy can be found at https://www.google.de/intl/de/policies/privacy/

Privacy policy for the use of Google Tag Manager

This website uses Google Tag Manager. This service allows website tags to be managed via an interface. Google Tag Manager only implements tags. This means: no cookies are used and no personal data is collected. Google Tag Manager triggers other tags, which may in turn collect data. However, Google Tag Manager does not access this data. If a deactivation has been made at the domain or cookie level, it will remain in effect for all tracking tags, provided they are implemented with Google Tag Manager.

Privacy policy regarding the use and application of Make

We use the integration service provider Make, operated by Celonis Inc. (USA).

Make is a service that automatically links actions or commands between multiple web tools and synchronizes applications and form data with one another.

The use of Make is based on Art. 6(1)(f) GDPR. An adequate level of data protection is ensured, as Celonis Inc. is certified under the EU-U.S. Data Privacy Framework.

Further information on data protection can be found at https://www.celonis.com/de/privacy-policy

Privacy policy regarding the use and application of Perspective

We use services provided by Perspective Software GmbH, Müggelstraße 22, 10247 Berlin (hereinafter: "Perspective"), on our website to provide interactive mobile funnels. As part of these funnels, personal data is transmitted and processed by Perspective via SSL encryption, provided you have given your consent.

Processing is based on Art. 6(1)(a) GDPR. The data is used exclusively to improve funnel functionality and for marketing and analytical purposes.

Perspective processes the data within the EU. Data is only transferred to third countries if appropriate security measures are in place, such as the EU Commission's standard contractual clauses.

Further information on data processing by Perspective can be found in Perspective's privacy policy: https://www.perspective.co/de/datenschutzerklaerung

You may revoke your consent to the processing of your data at any time with future effect by adjusting the cookie settings on our website accordingly or by contacting us via email.

Privacy policy regarding the use and application of Visual Website Optimizer

This website uses the software solution VWO (Visual Website Optimizer) to optimize its online presence, which evaluates website usage by measuring anonymized data. Based on the information gained about the needs of website users, the user-friendliness of the online presence is subsequently permanently increased. The software uses cookies for this purpose. You can refuse the setting of these cookies at any time by adjusting your browser settings accordingly. Further information can be found in the privacy policy of VWO. If you do not wish to be tracked by VWO, you can object to this here.

Universal Event Tracking (UET)

On our website, data is collected and stored using Microsoft Ads technologies, from which usage profiles are created using pseudonyms. This is a service provided by Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA. This service allows us to track user activity on our website if they have reached our website via Microsoft Ads. If you reach our website via such an ad, a cookie is set on your computer. A UET tag is integrated into our website. This is a code that, in conjunction with the cookie, stores some non-personal data about the use of the website. This includes, among other things, the time spent on the website, which areas of the website were accessed, and which ad the users used to reach the website. Information about your identity is not collected.

The collected information is transmitted to Microsoft servers in the USA and stored there for a maximum of 180 days. You can prevent the collection of data generated by the cookie and related to your use of the website as well as the processing of this data by deactivating the setting of cookies. This may limit the functionality of the website under certain circumstances.

In addition, Microsoft may, under certain circumstances, track your usage behavior across several of your electronic devices through so-called cross-device tracking and is thus able to display personalized advertising on or in Microsoft websites and apps. You can deactivate this behavior at http://choice.microsoft.com/en-us/opt-out.

Further information on Microsoft's analysis services can be found on the Microsoft Ads website (https://help.bingads.microsoft.com/#apex/3/en/53056/2). Further information on data protection at Microsoft can be found in Microsoft's privacy policy (https://privacy.microsoft.com/en-us/privacystatement).

Microsoft Clarity

We use Microsoft Clarity to analyze the usage behavior of our website. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in the analysis, optimization, and economic operation of our website.

For analysis purposes, Clarity logs mouse movements and creates a graphical representation of the parts of the website with which users interact most frequently (heatmaps). Clarity can also record sessions, allowing us to view website usage in the form of videos. In addition, Clarity provides us with information on general user behavior within our website, which we use to derive improvement measures.

When analyzing with Microsoft Clarity, usage data (in particular access times, mouse movements), meta/communication data (e.g., information on device, browser, and IP addresses), and location data (information on the geographical position of the accessing device) are processed in pseudonymized form (IP masking).

Privacy policy for the use of the LinkedIn Insight Tag

Within our online services, we use the marketing functions (the "LinkedIn Insight Tag") of the LinkedIn network. The provider is LinkedIn Ireland Unlimited Company, based in Ireland. Every time one of our pages containing LinkedIn functions is accessed, a connection to LinkedIn's servers is established. LinkedIn is informed that you have visited our websites with your IP address. With the help of the LinkedIn Insight Tag, we can, in particular, analyze the success of our campaigns within LinkedIn or determine target groups for them based on user interaction with our online services. If you are registered with LinkedIn, LinkedIn can associate your interaction with our online services with your user account. Even if you click the LinkedIn "Recommend" button and are logged into your LinkedIn account, LinkedIn can associate your visit to our website with you and your user account. Privacy Policy: https://www.linkedin.com/legal/privacy-policy, Opt-Out: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.

Legal basis for processing

Art. 6(1)(a) GDPR serves as the legal basis for our company for processing operations for which we obtain consent for a specific processing purpose. If the processing of personal data is necessary for the performance of a contract to which the data subject is a party, as is the case, for example, with processing operations necessary for the supply of goods or the provision of any other service or consideration, the processing is based on Art. 6(1)(b) GDPR. The same applies to such processing operations that are necessary for the implementation of pre-contractual measures, for example in cases of inquiries about our products or services. If our company is subject to a legal obligation by which processing of personal data becomes necessary, such as for the fulfillment of tax obligations, the processing is based on Art. 6(1)(c) GDPR. In rare cases, the processing of personal data might become necessary to protect vital interests of the data subject or another natural person. This would be the case, for example, if a visitor were injured in our facility and their name, age, health insurance data, or other vital information had to be passed on to a doctor, hospital, or other third party. Then the processing would be based on Art. 6(1)(d) GDPR. Finally, processing operations could be based on Art. 6(1)(f) GDPR. Processing operations that are not covered by any of the aforementioned legal bases are based on this legal basis if the processing is necessary to safeguard a legitimate interest of our company or a third party, provided that the interests, fundamental rights, and fundamental freedoms of the data subject do not override these. Such processing operations are permitted to us in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed if the data subject is a customer of the controller (Recital 47, sentence 2 GDPR).

Legitimate interests in processing pursued by the controller or a third party

If the processing of personal data is based on Article 6(1)(f) GDPR, our legitimate interest is the conduct of our business activities for the benefit of the well-being of all our employees and our shareholders.

Legal or contractual requirements for the provision of personal data; necessity for the conclusion of the contract; obligation of the data subject to provide the personal data; possible consequences of failure to provide such data

We would like to inform you that the provision of personal data is partly required by law (e.g., tax regulations) or may result from contractual provisions (e.g., information about the contractual partner). Sometimes, it may be necessary for a contract to be concluded if a data subject provides us with personal data, which must subsequently be processed by us. For example, the data subject is obliged to provide us with personal data when our company enters into a contract with them. Failure to provide the personal data would mean that the contract with the data subject could not be concluded. Before providing personal data, the data subject must contact one of our employees. Our employee will clarify to the data subject on a case-by-case basis whether the provision of personal data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the personal data, and what the consequences of not providing the personal data would be.

Existence of automated decision-making

As a responsible company, we do not use automated decision-making or profiling.

Data Protection Officer

We have appointed a data protection officer.

Contact details:

Attorney at Law
Stephan Hansen-Oest
Im Tal 10a
24939 Flensburg

Email: kanzlei@hansen-oest.com