Privacy

Microsoft Teams Privacy Information

Last updated: Editorial revision: clarified details on the categories of data processed, recipients and retention periods.

1. Purpose of processing

We use the »Microsoft Teams« tool to hold telephone conferences, online meetings, video conferences and/or web conferences (hereinafter: »online meetings«). »Microsoft Teams« is a service provided by Microsoft Corporation.

2. Controller

The controller for data processing directly related to the holding of »online meetings« is DextraData GmbH.

Please note: Insofar as you access the »Microsoft Teams« website, the provider of »Microsoft Teams« is responsible for the data processing. However, accessing the website is only necessary for using »Microsoft Teams« in order to download the software required to use »Microsoft Teams«.

If you do not wish to or cannot use the »Microsoft Teams« app, you can also use »Microsoft Teams« via your browser. In that case the service is also provided via the »Microsoft Teams« website.

3. Which data are processed?

Various types of data are processed when using »Microsoft Teams«. The scope of the data also depends on the information you provide before or during participation in an »online meeting«.

The following personal data are subject to processing:

User details: e.g. display name, email address where applicable, profile picture (optional), preferred language

Meeting metadata: e.g. date, time, meeting ID, telephone numbers, location

Text, audio and video data: You may have the option of using the chat function in an »online meeting«. In this respect, the text you enter is processed in order to display it in the »online meeting«. To enable video display and audio playback, the data from the microphone of your device and from any video camera of the device are processed for the duration of the meeting. You can switch off or mute the camera or the microphone yourself at any time via the »Microsoft Teams« applications.

4. Scope of processing

We use »Microsoft Teams« to hold »online meetings«. If we wish to record »online meetings«, we will inform you of this transparently in advance and – where required – ask for your consent.

Chat contents are logged when Microsoft Teams is used. Files shared by users in chats are stored in the OneDrive for Business account of the user who shared the file. Files shared by team members in a channel are stored on the team's SharePoint site.

Automated decision-making within the meaning of Art. 22 GDPR is not used.

5. Legal bases for the data processing

Insofar as personal data of employees of DextraData GmbH are processed, Section 26 BDSG-neu (German Federal Data Protection Act) is the legal basis for the data processing. Should personal data not be required for the establishment, performance or termination of the employment relationship in connection with the use of »Microsoft Teams«, but nevertheless be an essential component of using »Microsoft Teams«, Art. 6 (1) (f) GDPR is the legal basis for the data processing. In these cases our interest lies in the effective conduct of »online meetings«.

In all other respects, the legal basis for the data processing when holding »online meetings« is Art. 6 (1) (b) GDPR, insofar as the meetings are held in the context of contractual relationships.

If no contractual relationship exists, the legal basis is Art. 6 (1) (f) GDPR. Here, too, our interest lies in the effective conduct of »online meetings«.

6. Recipients / transfer of data

Personal data processed in connection with participation in »online meetings« are generally not passed on to third parties unless they are specifically intended to be shared. Please note that the contents of »online meetings«, as with in-person meetings, frequently serve precisely to communicate information to customers, prospective customers or third parties and are therefore intended to be shared.

Other recipients: The provider of “Microsoft Teams” necessarily obtains knowledge of the above-mentioned data insofar as this is provided for under our data processing agreement with “Microsoft Teams”.

7. Data processing outside the European Union

Data processing outside the European Union (EU) generally does not take place, as we have limited our storage location to data centres in the European Union. However, we cannot rule out that data are routed via internet servers located outside the EU. This may be the case in particular if participants in an “online meeting” are located in a third country.

The data are, however, encrypted during transport over the internet and are therefore protected against unauthorised access by third parties.

8. Data protection officer

We have appointed a data protection officer. You can reach them at datenschutz[at]dextradata[dot]com.

9. Your rights as a data subject

You have the right to information about the personal data concerning you. You can contact us at any time to request this information.

In the case of a request for information that is not made in writing, we ask for your understanding that we may require evidence from you proving that you are the person you claim to be.

You also have the right to rectification or erasure or to restriction of processing, insofar as you are legally entitled to this.

Finally, you have a right to object to the processing within the scope of the statutory provisions.

A right to data portability also exists within the scope of the data protection provisions.

10. Erasure of data

We generally erase personal data when there is no longer any requirement for further storage. Such a requirement may exist in particular if the data are still needed in order to fulfil contractual services, to examine and grant or reject warranty and, where applicable, guarantee claims. In the case of statutory retention obligations, erasure can only be considered after the respective retention period has expired.

11. Right to lodge a complaint with a supervisory authority

You have the right to lodge a complaint about the processing of personal data by us with a data protection supervisory authority. The contact details of the authority responsible for us are:

Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen

Kavalleriestr. 2-4

40213 Düsseldorf

Telephone: 0211/38424-0

Fax: 0211/38424-10

Email: poststelle@ldi.nrw.de

12. Changes to this data protection information

We revise this data protection information in the event of changes to the data processing or on other occasions that make this necessary. You will always find the current version on this page.

13. Further information on data protection at Microsoft Corporation

https://privacy.microsoft.com/en-gb/privacystatement

https://www.microsoft.com/en-gb/trust-center