Privacy

Privacy Policy

Note: The data protection information on the use of »Microsoft Teams« can be found separately on this page.

We appreciate your interest in our company and your visit to our website.

With this privacy notice we would like to inform you in a clear, transparent and concise manner about the nature, scope and purposes of the personal data we collect, use and process, and to explain your rights as a data subject.

 

We process your personal data exclusively within the framework of the statutory data protection provisions. Your privacy is important to us. We treat the data protection and data security of our clients and partners with confidence in accordance with our motto “Trusted Advice”.

 

If you have further questions about data protection at DextraData, you are welcome to contact our data protection officer at datenschutz@dextradata.com or via the contact details given at the end of this privacy notice.

Controller

DextraData GmbH

Girardetstraße 4

45131 Essen

Germany

Tel.: +49 201 95 975 0

E-Mail: info@dextradata.com

Website: https://www.dextradata.com

Represented by the management: Shayan Faghfouri

Defined terms

The terms used in this privacy notice have the following meanings in accordance with the EU General Data Protection Regulation (EU GDPR or GDPR).

“personal data”: All information relating to an identified or identifiable natural person (hereinafter “data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more special characteristics which express the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;

“processing”: Any operation or set of operations which is performed on personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;

“restriction of processing”: The marking of stored personal data with the aim of limiting their future processing;

“pseudonymisation”: The processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures to ensure that the personal data are not attributed to an identified or identifiable natural person;

“controller”: The natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law;

“processor”: A natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller;

“recipient”: A natural or legal person, public authority, agency or other body to which personal data are disclosed, whether a third party or not. However, public authorities which may receive personal data in the framework of a particular inquiry under Union or Member State law shall not be regarded as recipients; the processing of those data by such authorities shall be in compliance with the applicable data protection rules according to the purposes of the processing;

“third party”: A natural or legal person, public authority, agency or body other than the data subject, the controller, the processor and persons who, under the direct authority of the controller or processor, are authorised to process the personal data;

“consent” of the data subject: Any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her;

Your rights as a data subject

You may exercise the following rights at any time via the contact details of our data protection officer given above:

  • Access to the personal data we hold about you and information about their processing (Art. 15 GDPR),
  • Rectification of inaccurate personal data (Art. 16 GDPR),
  • Erasure of your personal data held by us (Art. 17 GDPR),
  • Restriction of processing where we are not yet able to erase your data due to legal obligations (Art. 18 GDPR),
  • Objection to the processing of your personal data by us (Art. 21 GDPR), and
  • Data portability, where you have consented to the processing or have entered into a contract with us (Art. 20 GDPR).

When asserting the right to access as well as erasure, the restrictions of §§ 33, 34 BDSG-neu must be taken into account.

If you have given us consent, you may withdraw it at any time with effect for the future. To make contact in this regard, please use the contact details provided at the end of this privacy notice.

You may at any time lodge a complaint with a supervisory authority pursuant to Art. 77 GDPR in conjunction with § 19 BDSG-neu, e.g. the supervisory authority of the federal state of your residence or the supervisory authority responsible for us as the controller:

State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen)

P.O. Box 20 04 44

40102 Düsseldorf

Kavalleriestraße 2-4

40213 Düsseldorf

Phone: +49 211 384240

E-Mail: poststelle[at]ldi.nrw[dot]de

Homepage: https://www.ldi.nrw.de

A list of all supervisory authorities (for the non-public sector) with addresses can be found at: https://www.bfdi.bund.de/DE/Infothek/Anschriften_Links/anschriften_links-node.html.

Data categories

We have designed the development of the website to collect as little data from you as possible. However, certain processing purposes require the provision of specific personal data, e.g. in the context of newsletter or event registration, contacting us via the contact form or by e‑mail for the initiation of a contract up to contract conclusion. We take care to process your data only in accordance with a legal basis or your consent. We comply with the provisions of the General Data Protection Regulation (GDPR) in force since 25 May 2018 and the respective national data protection provisions or other more specific laws.

We process the following categories of personal data:

Data categoriesPurpose of processingLegal basisStorage period
Server log data: IP address, website usage data (log data about website accesses or file retrievals, e.g. name of the retrieved file, date and time of retrieval, amount of data transferred) and device information (e.g. operating system, browser type and version), cookie information in session cookiesNetwork communication<br>Functionality and security of the website<br>Detection and correction of malfunctions and errorsArt. 6(1)(1)(f) GDPR<br>Our legitimate interest in the temporary storage of the log data (server log files) and session cookie information lies in our interest in providing our website efficiently and securely.7 days<br>Session cookies are automatically deleted at the end of the browser session<br>Where further retention is required for evidentiary purposes, deletion will take place after final clarification of the incident
First name, last name, e‑mail addressLead generationArt. 6(1)(1)(a) GDPR180 days
Name, e‑mail address, telephone number, information about your matterContact (contact form)<br>Sending information material on request<br>Sending offers on request<br>Contract initiation and, where applicable, contract conclusionArt. 6(1)(1)(b) and (1)(1)(f) GDPRMax. 1 year
Contact details (e.g. first/last names of current and, where applicable, former contacts as well as name affixes, customer’s company name and address, mobile, landline telephone number with extension, e‑mail address, fax number)<br>Job‑related data (e.g. role in the company, department)<br>if applicable, bank details (in the context of a SEPA direct debit mandate also first/last name of the account holder (company))<br>if applicable, information on creditworthiness and credit behaviour (company)<br>if applicable, date of birth, length of employment or similar (for customer support purposes, if you provide us with this information voluntarily)Contract initiation and, where applicable, contract conclusionArt. 6(1)(1)(b) GDPRMaximum 1 year<br>In the event of contract conclusion: retention until the end of the contractual relationship and the expiry of statutory retention periods<br>If you provide us with data for customer support purposes voluntarily, these will be stored until revoked.
E‑mail addressNewsletter registration and deliveryArt. 6(1)(1)(a) GDPRUntil the user unsubscribes
First name, last name, e‑mail address, company nameEvent registrationArt. 6(1)(1)(a) GDPRMax. 1 year
Analytics data: IP address (partly anonymised, as described below), website usage data (cookie information)Website analysis and optimisation, marketing<br>Consent management (cookie banner)<br>Please also note the following informationArt. 6(1)(1)(a) and (1)(1)(f) GDPRDeletion of the cookies set is possible at any time under the section “Cookie settings and revocation” within this privacy policy as well as via the browser settings.<br>Deletion of stored data: see the following information.
Name, contact details, place of birth, date of birth, nationality, qualification documentsProcessing of the application procedure<br>In the event of contract conclusion: processing of the employment relationshipArt. 6(1)(1)(b) GDPR6 months<br>for example to meet an obligation to provide evidence in a possible procedure under the General Equal Treatment Act (AGG)<br>In the event of contract conclusion:<br>retention until the end of the employment relationship and the expiry of statutory retention periods

Recipients of data

Personal data are disclosed for the purpose of providing our website and delivering our services in particular to the following recipients: hosting providers, data centre operators, e‑mail marketing and tracking service providers, partners and manufacturers. Necessary data protection contracts have been concluded with all service providers. Other recipients are authorities such as tax offices and social security agencies within the scope of our legal reporting obligations (e.g. for the execution of employment relationships). In addition, credit reference agencies in the context of ordering our products.

Within our company we ensure that only those persons receive your data who need it to fulfil contractual and legal obligations. All employees are obliged to comply with data protection regulations.

Further information can be found below.

Further information on data processing

When visiting the website

Is there a legal obligation to provide the personal data?No
Is there a contractual necessity to provide the personal data?No
What are the possible consequences of not providing the data?Applies to contact and form fields: If you do not provide your data, the desired contact, the sending of information material, event registration and/or newsletter registration cannot take place.
Is automated decision‑making carried out?No
From which source do the personal data originate (if not collected from the data subject)?No data about you are obtained from third parties in the course of using our website.

Outside the website

Is there a legal obligation to provide the personal data?No
Is there a contractual necessity to provide the personal data?Yes – in the case of contract initiation (customer, partner, employee) and/or contract conclusion.
What are the possible consequences of not providing the data?If you do not provide your data, the desired contract initiation (e.g. sending an offer, arranging a job interview) and a contract conclusion cannot take place.
Is automated decision‑making carried out?No
From which source do the personal data originate (if not collected from the data subject)?In the course of contract initiation or during an ongoing contractual relationship we generally receive personal data from you. Exceptionally, in certain constellations your personal data are also collected from other sources. In certain cases we receive your personal data from our partners in order to be able to make you an offer on the basis of Art. 6(1)(1)(b) GDPR.<br>For ad‑hoc enquiries of relevant information, we obtain data from credit reference agencies (Crefo, Schufa), in particular regarding creditworthiness and credit behaviour.

Collection of general information when visiting our website

When you access our website, i.e. if you do not register or otherwise transmit information, information of a general nature is automatically collected. This information (server log files) includes, for example, the type of web browser, the operating system used, the domain name of your internet service provider, your IP address and similar.

They are processed in particular for the following purposes:

  • Ensuring a problem‑free connection to the website,
  • Ensuring smooth use of our website,
  • Evaluation of system security and stability, and
  • for further administrative purposes.

We do not use your data to draw conclusions about you as an individual. Information of this kind is possibly evaluated by us on a statistical basis in order to optimise our internet presence and the technology behind it.

Processing is carried out in accordance with Art. 6(1)(f) GDPR on the basis of our legitimate interest in improving the stability and functionality of our website.

The provision of the aforementioned personal data via our website is neither legally nor contractually required. Without the IP address, however, the service and the functionality of our website cannot be guaranteed. In addition, individual services and features may not be available or may be limited. For this reason, objection is not possible.

Form fields/TLS encryption

Unfortunately, the transmission of information via the Internet is never completely secure; therefore we cannot guarantee the security of data transmitted to our website over the Internet.

However, we protect our website by technical and organisational measures against loss, destruction, access, alteration or dissemination of your data by unauthorised persons.

In particular, your personal data are transmitted to us in encrypted form. We use the encoding systems SSL/TLS (Secure Sockets Layer/Transport Layer Security). You can recognise an encrypted connection by the "https://" address line of your browser and by the padlock symbol in the browser bar. This means that data you transmit via this website cannot be read by third parties. Our security measures are continuously improved in line with technological developments.

If you send us enquiries, for example via the contact form, the details you provide in the enquiry form, including the contact details you provide there, will be stored by us for the purpose of processing the enquiry and in case of follow-up questions. We do not pass on these data without your consent.

Data collection when providing content via our website

When registering to use our personalised services (e.g. downloads), certain personal data are collected, such as name, address, contact and communication details (e.g. telephone number and email address). After registration you can access the specific content for which you registered.

The provision of your personal data is voluntary and is based solely on your consent. Without providing your personal data we cannot grant you access to the content and services we offer.

The processing of the data entered during registration is based on your consent (Art. 6(1)(a) GDPR).

Data will only be processed in this context for as long as the relevant consent exists. Afterwards they will be deleted, provided that no statutory retention obligations prevent this. For contact in this regard, please use the contact details given at the end of this privacy policy.

Contact

You can contact us via the contact form on our website. The personal data you submit will be stored in order to process your request and to contact you for the purpose of handling it.

Providing your personal data is voluntary. However, we can only process your request if you provide us with your name, your email address and the reason for your enquiry.

The processing of the data entered into the contact form is based on a legitimate interest (Art. 6(1)(f) GDPR).

If you contact us to request a quote, the processing of the data takes place for the performance of pre-contractual measures (Art. 6(1)(b) GDPR).

The data entered via the contact form will be deleted no later than 6 months after the request has been processed. If a contractual relationship is concluded, we are subject to the statutory retention periods under the HGB and will delete your data after these periods have expired.

You can also contact us by email. In this case too, we store the personal data you send to us in order to process your request and to contact you for the purpose of handling it. These data are likewise provided to us by you on a purely voluntary basis.

The details for contacting us by email can be found in this privacy policy and in our imprint.

Cookies

Like many other websites, we also use so-called "cookies". Cookies are small text files that are stored on your device (laptop, tablet, smartphone, etc.) when you visit our website.

This gives us certain data such as IP address, browser used and operating system.

Cookies cannot be used to start programmes or to transmit viruses to a computer. Based on the information contained in cookies we can make navigation easier for you and ensure the correct display of our web pages.

Of course, you can generally view our website without cookies. Internet browsers are regularly set to accept cookies. In general, you can disable the use of cookies at any time via the settings of your browser. Please use the help functions of your Internet browser to find out how to change these settings. Please note that certain functions of our website may not work if you have disabled the use of cookies.

Storage duration and cookies used:

On this website we use exclusively the cookies and cookie-like storage technologies listed below. Cookies in the "Marketing" category are only set after you have given your consent in the cookie banner.

ProviderNameCategoryFunctionStorage duration
DextraData (diese Website)dd-cookie-consentNecessary (Local Storage)Stores your cookie consent or its rejection so that the banner does not appear againUntil deletion by you or until a change of the consent version
DextraData (diese Website)dd-localeNecessary (Session Storage)Stores the language version you have selected (DE/EN)End of the browser session
HubSpot (Kontaktformular)__cf_bmMarketing (third party, hsforms.com / hsforms.net)Cloudflare bot management: distinguishing between human visitors and bots when loading the embedded HubSpot form30 minutes
HubSpot (Kontaktformular)hubspotutk, __hstc, __hssrc, __hsscMarketing (third party)May be set when using or submitting the HubSpot form in order to associate your form request with a browser and detect multiple submissionsSession to 6 months

Without your consent to the "Marketing" category the HubSpot form will not be loaded; in this case no third-party cookies will be set and no data will be transmitted to HubSpot. If you revoke your consent, the form will no longer be loaded; cookies already set by hsforms.com/hsforms.net will expire automatically and can be deleted at any time via your browser settings.

We do not use any analytics or tracking services such as Google Analytics, Google Ads, LinkedIn Insight or embedded YouTube videos on this website.

To the extent that these cookies may also relate to personal data, we will inform you about this in the following sections.

You can delete individual cookies or the entire cookie store via your browser settings. In addition, you can find information and instructions on how these cookies can be deleted or blocked in advance. Depending on your browser provider, the necessary information can be found at the links below:

Website analysis and marketing tools

Google Analytics

Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043 USA (provider of Google Analytics), https://marketingplatform.google.com/about/analytics/

This website uses Google Analytics, a web analytics service provided by Google Inc. Through Analytics it is possible to assign data, sessions and interactions across multiple devices to a pseudonymous user ID and thereby analyse a user’s activities across devices.

Google Analytics uses cookies that enable an analysis of your use of the website. The information generated by the cookie about your use of this website is generally transferred to and stored on a Google server in the USA. However, by activating IP anonymisation on this website your IP address is first shortened by Google within member states of the European Union or in other Contracting States of the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there. The IP address transmitted by your browser as part of Google Analytics will not be combined with other Google data. On our behalf Google will use this information to evaluate your use of the website, to compile reports on website activity and to provide us with other services related to website and internet use.

An analysis of your usage behaviour using Google Analytics is carried out only with your explicit consent (Opt-In). You may withdraw your consent at any time with effect for the future by clicking the appropriate option in the cookie banner. The legal basis for the use of Google Analytics is Art. 6(1)(1)(a) GDPR.

Google is headquartered in the USA. The European Court of Justice (ECJ) has found that the USA does not provide a level of data protection equivalent to that guaranteed under European law ( ECJ, 16 July 2020 – C-311/18 “Schrems II”, press release). In particular, there is a risk that your data may be accessed by US authorities for control and surveillance purposes and possibly processed without effective legal remedies (for example due to Section 702 of the Foreign Intelligence Surveillance Act ( FISA 702). By accepting Google cookies you also consent, having been made aware of the possible risks in accordance with Art. 49(1)(1)(a) GDPR, to the processing of your data in the USA.

The data we send and that are linked to cookies, user identifiers (e.g. User-ID) or advertising IDs are automatically deleted after 14 months. The deletion of data whose retention period has been reached takes place automatically once a month.

You can prevent the storage of cookies by configuring your browser software accordingly; however, please note that in this case you may not be able to use all the functions of this website in full. You can also prevent the collection of the data generated by the cookie and relating to your use of the website (including your IP address) being sent to Google and the processing of these data by Google by downloading and installing the browser plugin available via the following link: Browser add-on to disable Google Analytics.

Further information can be found in Google’s Terms of Use and Privacy Policy.

Google Ads

Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043 USA (provider of Google Ads), https://ads.google.com/home

We use Google Ads, a service of Google Inc. Google Ads uses cookies to display user-based advertising. The cookies recognise which advert has already been shown in your browser and whether you have visited a website via a displayed advert.

We display interest-based advertising to you only with your explicit consent (Opt-In). You may withdraw your consent at any time with effect for the future. The legal basis for the use of Google Ads is Art. 6(1)(1)(a) GDPR.

Google is headquartered in the USA. The European Court of Justice (ECJ) has found that the USA does not provide a level of data protection equivalent to that guaranteed under European law ( ECJ, 16 July 2020 – C-311/18 “Schrems II”, press release). In particular, there is a risk that your data may be accessed by US authorities for control and surveillance purposes and possibly processed without effective legal remedies (for example due to Section 702 of the Foreign Intelligence Surveillance Act ( FISA 702). By accepting Google cookies you also consent, having been made aware of the possible risks in accordance with Art. 49(1)(1)(a) GDPR, to the processing of your data in the USA.

You can prevent the storage of cookies by configuring your browser software accordingly; however, please note that in this case you may not be able to use all the functions of this website in full.

Further information can be found in Google’s Terms of Use and Privacy Policy.

Google Tag Manager

Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043 USA (provider of Google Tag Manager), https://www.google.com/intl/de/tagmanager/.

For reasons of transparency we point out that we use Google Tag Manager. The Google Tag Manager itself does not collect any personal data. The Tag Manager enables us to more easily embed and manage our tags. Tags are small pieces of code that are used, among other things, to measure traffic and visitor behaviour, to record the impact of online advertising and social channels, to set up remarketing and audience targeting, and to test and optimise websites. We use the tools described in these privacy provisions for these purposes. If you have disabled tracking, this will remain in effect for all tracking tags that were implemented with this Tag Manager.

The use of Google Tag Manager is only with your explicit consent (Opt-In). You may withdraw your consent at any time with effect for the future. The legal basis for the use of Google Tag Manager is Art. 6(1)(1)(a) GDPR.

Google is headquartered in the USA. The European Court of Justice (ECJ) has found that the USA does not provide a level of data protection equivalent to that guaranteed under European law ( ECJ, 16 July 2020 – C-311/18 “Schrems II”, press release). In particular, there is a risk that your data may be accessed by US authorities for control and surveillance purposes and possibly processed without effective legal remedies (for example due to Section 702 of the Foreign Intelligence Surveillance Act ( FISA 702). By accepting Google cookies you also consent, having been made aware of the possible risks in accordance with Art. 49(1)(1)(a) GDPR, to the processing of your data in the USA.

Further information about Google Tag Manager can be found at: https://www.google.com/intl/de/tagmanager/use-policy.html.

LinkedIn Pixel

LinkedIn Corporation, 2029 Stierlin Court, Mountain View, California 94043, USA (provider of the LinkedIn Pixel), https://www.linkedin.com/

We use LinkedIn’s conversion tracking technology and retargeting function on our website. With the help of this technology personalised adverts may be displayed to visitors of this website on LinkedIn. It is also possible to create anonymous reports about the performance of the adverts as well as information about interaction with the website. To this end the LinkedIn Insight Tag (LinkedIn Pixel) is embedded on this website, which establishes a connection to LinkedIn’s servers when you visit this website and give your consent.

An analysis of your usage behaviour using the LinkedIn Pixel is carried out only with your explicit consent (Opt-In). You may withdraw your consent at any time with effect for the future. The legal basis for the use of the LinkedIn Pixel is Art. 6(1)(1)(a) GDPR.

LinkedIn Corporation is headquartered in the USA. The European Court of Justice (ECJ) has found that the USA does not provide a level of data protection equivalent to that guaranteed under European law ( ECJ, 16 July 2020 – C-311/18 “Schrems II”, press release). In particular, there is a risk that your data may be accessed by US authorities for control and surveillance purposes and possibly processed without effective legal remedies (for example due to Section 702 of the Foreign Intelligence Surveillance Act ( FISA 702). By accepting LinkedIn cookies you also consent, having been made aware of the possible risks in accordance with Art. 49(1)(1)(a) GDPR, to the processing of your data in the USA.

Further information on how LinkedIn handles user data can be found in LinkedIn’s privacy policy.

Marketo

Marketo Inc., 901 Mariners Island Blvd. Suite 500, San Mateo, CA 94404, USA (provider of the Marketo Munchkin token) https://www.marketo.com/

We use the Marketo tool on our website, a service of Marketo EMEA Ltd., Red Oak North, South County Business Park, Leopardstown, Dublin 18, Ireland (“Marketo”), to collect statistical data about the use of our web offering and to optimise our offering accordingly, to provide system-related emails, information about individual browsing behaviour, downloads of white papers, fact sheets, case studies and similar materials, and to conduct email marketing.

One or more cookies are stored on your computer to collect data for marketing and optimisation purposes which are stored and further processed on Marketo’s servers. The data collected can be combined with the personal data you have voluntarily provided on the website for profiling. You can object to profiling by disabling cookies in your browser. If you have given us your consent, we also use your data to inform you about our products and news. Further information can be found in Marketo’s privacy statements at de.marketo.com/vertrauen/legal/datenschutz.

Marketo’s data centres where customer data of European customers are stored and processed are located in the United Kingdom and process data only within Europe. The only exception is the storage/processing of service data. Marketo offers a 24-hour service whose requests are also processed in the USA, among other places. For these exceptional purposes certain service data must also be processed on US servers.

Marketo is headquartered in the USA. The European Court of Justice (ECJ) has found that the USA does not provide a level of data protection equivalent to that guaranteed under European law ( ECJ, 16 July 2020 – C-311/18 “Schrems II”, press release). In particular, there is a risk that your data may be accessed by US authorities for control and surveillance purposes and possibly processed without effective legal remedies (for example due to Section 702 of the Foreign Intelligence Surveillance Act ( FISA 702). By accepting Marketo cookies you also consent, having been made aware of the possible risks in accordance with Art. 49(1)(1)(a) GDPR, to the processing of your data in the USA.

You can prevent the storage of cookies by configuring your browser software accordingly; however, please note that in this case you may not be able to use all the functions of this website in full.

Further information about the purpose and scope of data collection and its processing by Marketo can be found in Marketo’s privacy policy: documents.marketo.com/de/legal/datenschutz/. There you can also find further information about your rights in this regard.

The processing of your data is based on Art. 6(1)(a) GDPR (consent) if you have consented to the processing of your data by Marketo within our cookie policy.

Your activity data collected via Marketo will be deleted upon your request, but at the latest in accordance with Marketo’s Data Retention Policy: nation.marketo.com/docs/DOC-5765-marketo-activities-data-retention-policy-under-the-hood

XING-Pixel

XING AG, Gänsemarkt 43, 20354 Hamburg (provider of the XING Pixel), https://www.xing.com/

We use XING’s tracking technology on our website for the placement of audience-targeted online advertising and for conversion tracking. For this purpose, we have implemented a XING tag (XING Pixel) on our website. When you visit our website and after your consent, this tag establishes a direct connection to XING’s servers and transmits that you have visited our website and whether you have made an enquiry or taken any other action. XING assigns this information to your personal XING user account. This allows us to display targeted ads (remarketing) based on your previous page views and activities. The data processed by XING in this context does not permit us to identify you personally. The pseudonymous data is not merged by us with any other information about you.

An analysis of your usage behaviour via the XING Pixel takes place exclusively after your explicit consent (opt-in). You may withdraw your consent at any time with effect for the future. The legal basis for the use of the XING Pixel is Art. 6(1)(1)(a) GDPR.

Further information on how XING handles user data, as well as your rights and settings options to protect your privacy, can be found in XING’s privacy policy.

Seismic

Seismic Corporation, 100 Summer Street, 16th Floor, Boston, MA 02110, USA (provider of Seismic), https://www.seismic.com/

We use Seismic’s analytics technology to optimise our content and marketing strategies. By using Seismic we can analyse user behaviour in order to provide you with more relevant content and personalised marketing messages.

The data collected by Seismic may be used to compile reports on website activity and to improve our online experience. These data may include aggregated information about visitor numbers, page views and interaction patterns.

The security of your data is important to us. We take your privacy seriously and use Seismic in accordance with applicable data protection regulations, including the General Data Protection Regulation (GDPR). Your personal data will not be shared with third parties or used for purposes other than improving our marketing efforts.

Seismic is headquartered in the USA. The European Court of Justice (EuGH) found that the USA does not provide an adequate level of data protection equivalent to European law ( EuGH, 16.7.2020 – C-311/18 “Schrems II”, press release). There is, in particular, a risk that your data could be accessed by US authorities for control and surveillance purposes and possibly processed without effective legal remedies (for example pursuant to Section 702 of the Foreign Intelligence Surveillance Act (FISA 702)). By accepting Seismic cookies you thereby consent, being aware of the possible risks, pursuant to Art. 49(1)(1)(a) GDPR that your data will be processed in the USA.

Further information on data protection and data security when using Seismic can be found in Seismic’s privacy policy at https://seismic.com/de/privacy-policy/

Social Media Plug-ins under Use of the Shariff Solution

Social plugins (“plugins”) from social networks are used on our website. To increase the protection of your data when you visit our website, the plugins are not embedded without restriction but only via an HTML link (the so-called “Shariff solution” from c´t). This integration ensures that, when a page of our website containing such plugins is called up, no connection to the servers of the provider of the respective social network is established yet. If you click on one of the buttons, a new window of your browser will open and load the page of the respective service provider, where you can (if necessary after entering your login details) for example press the Like or Share button. The purpose and scope of the data collection and the further processing and use of the data by the providers on their pages, as well as your rights and settings options to protect your privacy, can be found in the providers’ privacy notices:

http://www.facebook.com/policy.php

https://policies.google.com/privacy

https://www.linkedin.com/legal/privacy-policy.

https://www.xing.com/app/share?op=data_protection

https://twitter.com/privacy

External Media

Adobe Typekit

Adobe Systems Incorporated: 345 Park Avenue, San Jose, California 95110-2704, USA

Adobe Systems Software Ireland Limited: 4-6 Riverwalk, City West Business Campus, Saggart, Dublin 24, Ireland ( https://www.adobe.com)

This site uses so-called web fonts provided by Adobe Typekit for a consistent presentation of fonts. When you call up a page, your browser loads the required web fonts into its browser cache in order to display texts and fonts correctly.

To this end, the browser you are using must establish a connection to the servers of Adobe Typekit. As a result, Adobe Typekit gains knowledge that our website was accessed via your IP address. The use of Adobe Typekit web fonts is in the interest of a uniform and attractive presentation of our online offerings. This represents a legitimate interest within the meaning of Art. 6(1)(f) GDPR.

If your browser does not support web fonts, a standard font from your computer is used.

Adobe is headquartered in the USA. The European Court of Justice (EuGH) has found that the USA does not provide an adequate level of data protection equivalent to European law ( EuGH, 16.7.2020 – C-311/18 “Schrems II”, press release). There is, in particular, a risk that your data could be accessed by US authorities for control and surveillance purposes and possibly processed without effective legal remedies (for example pursuant to Section 702 of the Foreign Intelligence Surveillance Act (FISA 702)). By accepting Adobe cookies you thereby consent, being aware of the possible risks, pursuant to Art. 49(1)(1)(a) GDPR that your data will be processed in the USA.

Further information on Adobe Typekit web fonts can be found at https://typekit.com/ and in Adobe Typekit’s privacy statement: https://www.adobe.com/de/privacy/policies/typekit.html

Google Maps

Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland (“Google”) ( https://www.google.com)

On our website we use Google Maps (API) from Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland (“Google”). Google Maps is a web service for displaying interactive maps in order to represent geographical information visually. By using this service our location is shown to you and any route to us is made easier.

Already when you call up the subpages in which the Google Maps map is embedded, information about your use of our website (such as your IP address) is transmitted to Google servers and stored there; this may also result in a transfer to the servers of Google LLC in the USA. This occurs regardless of whether Google provides a user account through which you are logged in or whether a user account exists. If you are logged in to Google, your data will be directly assigned to your account. If you do not want this assignment to be made to your Google profile, you must log out of Google before activating the button. Google stores your data (including for users who are not logged in) as usage profiles and evaluates them. The collection, storage and analysis are carried out pursuant to Art. 6(1)(f) GDPR on the basis of Google’s legitimate interest in displaying personalised advertising, market research and/or the demand-based design of Google websites. You have a right to object to the creation of these user profiles; to exercise this right you must contact Google.

Google is headquartered in the USA. The European Court of Justice (EuGH) has found that the USA does not provide an adequate level of data protection equivalent to European law ( EuGH, 16.7.2020 – C-311/18 “Schrems II”, press release). There is, in particular, a risk that your data could be accessed by US authorities for control and surveillance purposes and possibly processed without effective legal remedies (for example pursuant to Section 702 of the Foreign Intelligence Surveillance Act (FISA 702)). By accepting Google cookies you thereby consent, being aware of the possible risks, pursuant to Art. 49(1)(1)(a) GDPR that your data will be processed in the USA.

If you do not agree to the future transfer of your data to Google in the context of using Google Maps, you can also completely deactivate the Google Maps web service by switching off JavaScript in your browser. Google Maps and thus the map display on this website can then no longer be used.

You can view Google’s terms of use at https://www.google.de/intl/de/policies/terms/regional.html, the additional terms of use for Google Maps can be found at https://www.google.com/intl/de_US/help/terms_maps.html

Detailed information on data protection in connection with the use of Google Maps can be found on Google’s website (“Google Privacy Policy”): https://www.google.de/intl/de/policies/privacy/

YouTube

Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (provider of YouTube), https://www.youtube.com/?gl=DE.

Within our website we embed videos from the YouTube platform. For this purpose the videos are loaded directly from the YouTube servers. In doing so, your IP address is automatically transmitted to the YouTube server, as well as which of our pages you visited. If you are logged into your YouTube account, this enables Google to directly associate your usage behaviour with your personal profile.

The display of videos from YouTube takes place only after your explicit consent (opt-in). You may withdraw your consent at any time with effect for the future. The legal basis for the use of YouTube is Art. 6(1)(1)(a) GDPR.

Google LLC has its headquarters in the USA. The Court of Justice of the European Union (CJEU) has determined that the USA does not provide a level of data protection equivalent to that of European data protection law (CJEU, 16 July 2020 – C-311/18 “Schrems II”, press release). There is in particular a risk that your data may be processed by US authorities for control and surveillance purposes and possibly without effective legal remedies (for example pursuant to Section 702 of the Foreign Intelligence Surveillance Act (FISA 702)). By accepting cookies from Google you simultaneously consent, being aware of the possible risks, pursuant to Art. 49(1)(1)(a) GDPR to your data being processed in the USA.

Further information can be found in the Terms of Service and the Privacy Policy of Google.

Cookie settings and withdrawal

Withdrawal of cookie settings/Cookie settings

Note: You can also prevent the storage of cookies at any time by configuring your browser software accordingly. There you can also allow only certain types of cookies or delete individual or all cookies. We would, however, like to point out that in that case you may not be able to use all functions of this website in full.

Social Media

We maintain so-called fan pages or accounts or channels on the networks listed below in order to provide you with information and offers within social networks and to offer you additional ways to contact us and to learn about our offers. Below we inform you about which data we or the respective social network process about you in connection with the access to and use of our fan pages/accounts.

Data we process about you

If you wish to contact us by messenger or via direct message through the respective social network, we will generally process your username through which you contact us and may store further data you provide to the extent necessary to handle/answer your request.

The legal basis is Art. 6(1)(1)(f) GDPR (processing is necessary for the purposes of the legitimate interests pursued by the controller).

(Static) usage data we receive from the social networks

We obtain statistics automatically provided via insights functionalities concerning our accounts. The statistics include, among other things, the total number of page views, likes, information on page activity and post interactions, reach, video views/plays and information on the proportion of men/women among our fans/followers.

The statistics contain only aggregated data that cannot be related to individual persons. They do not enable us to identify users.

Which data the social networks process about you

To view the contents of our fan pages or accounts you do not have to be a member of the respective social network and a user account for the respective social network is not required for this purpose.

Please note, however, that the social networks do collect and store data from website visitors without a user account when the respective social network is accessed (e.g. technical data to display the website to you) and use cookies and similar technologies, over which we have no influence. Details can be found in the privacy policies of the respective social network (see the corresponding links above).

If you wish to interact with the content on our fan pages/accounts, e.g. comment on, share or like our posts/contributions and/or contact us via messenger functions, prior registration with the respective social network and the provision of personal data is required.

We have no influence on the data processing carried out by the social networks in the context of your use. To our knowledge, your data are stored and processed by the social networks in particular in connection with the provision of the services of the respective social network, and also for the analysis of usage behaviour (using cookies, pixels/web beacons and similar technologies) based on which interest-based advertising is displayed both inside and outside the respective social network. It cannot be ruled out that your data may be stored by the social networks outside the EU/EEA and disclosed to third parties.

Information, among other things, on the exact scope and the purposes of the processing of your personal data, the retention/deletion period and policies on the use of cookies and similar technologies in the context of registration and use of the social networks can be found in the privacy policies/cookie policies of the social networks. There you will also find information on your rights and objection options.

Facebook Page

When visiting our Facebook page, Facebook, among other things, records your IP address as well as further information that is present in the form of cookies on your PC. This information is used to provide us, as operators of the Facebook pages, with statistical information about the use of the Facebook page. Further information on this is provided by Meta Platforms Ireland Limited at the following link:

https://facebook.com/help/pages/insights.

By means of the transmitted statistical information it is not possible for us to draw conclusions about individual users. We use these data only to address the interests of our users and to continually improve our online presence and ensure its quality.

We collect your data via our fan page only in order to enable possible provision for communication and interaction with us. This collection usually includes your name, message contents, comment contents as well as profile information you have made “public”.

The processing of your personal data for the purposes set out above is based on our legitimate commercial and communicative interest in providing an information and communication channel pursuant to Art. 6(1)(1)(f) GDPR. If you as a user have given consent to the data processing to the respective provider of the social network, the legal basis for the processing extends to Art. 6(1)(a), Art. 7 GDPR.

Due to the fact that the actual data processing is carried out by the provider of the social network, our access to your data is limited. Only the provider of the social network is authorised to have full access to your data. For this reason only the provider can directly take corresponding measures to fulfil your user rights (request for information, deletion request, objection, etc.) and implement them. Asserting the corresponding rights is therefore most effective directly against the respective provider.

We are jointly responsible with Meta Platforms Ireland Limited for the personal data content of the Facebook fan page. Data subject rights may be asserted against Meta Platforms Ireland Limited as well as against us.

Primary responsibility for the processing of insights data lies, in accordance with the GDPR, with Meta Platforms Ireland Limited. It is also responsible for fulfilling all obligations under the GDPR with regard to the processing of insights data. Meta Platforms Ireland Limited provides the essentials of the Pages Insights addendum to the data subjects.

We do not make decisions regarding the processing of insights data and all further information required by Art. 13 GDPR, including the legal basis, the identity of the controller and the storage duration of cookies on user devices, is provided by the provider.

The Meta Platforms Ireland Limited Inc. has its headquarters in the USA. The Court of Justice of the European Union (CJEU) has determined that the USA does not provide a level of data protection equivalent to that of European data protection law (CJEU, 16 July 2020 – C-311/18 “Schrems II”, press release). There is in particular a risk that your data may be processed by US authorities for control and surveillance purposes and possibly without effective legal remedies (for example pursuant to Section 702 of the Foreign Intelligence Surveillance Act (FISA 702)). By accepting cookies from Facebook you simultaneously consent, being aware of the possible risks, pursuant to Art. 49(1)(1)(a) GDPR to your data being processed in the USA.

Further information can be found directly on Facebook (Page Controller Addendum with Meta): https://www.facebook.com/legal/terms/page_controller_addendum.

LinkedIn page

LinkedIn is a social network run by LinkedIn Inc., headquartered in Sunnyvale, California, USA, which enables the creation of private and professional profiles. Users can maintain existing contacts and make new ones. Companies can create profiles on which photos and other company information are uploaded. Other LinkedIn users have access to this information and can write their own articles and share that content with others.

The focus is on professional exchange about specialist topics with people who have the same professional interests. In addition, LinkedIn is frequently used by companies and other organisations to recruit staff and to present themselves as attractive employers.

Further information about LinkedIn can be found at: https://about.linkedin.com/

The LinkedIn Corporation is headquartered in the USA. The Court of Justice of the European Union (CJEU) found that the USA does not provide a level of data protection that is equivalent to European data protection law (CJEU, 16.7.2020 – C-311/18 “Schrems II”, press release). There is in particular a risk that your data may be processed by US authorities for control and surveillance purposes and possibly also without effective legal remedies (for example under Section 702 of the Foreign Intelligence Surveillance Act (FISA 702)). By accepting cookies from LinkedIn, you thereby consent, with knowledge of the possible risks in accordance with Art. 49(1)(1)(a) GDPR, to your data being processed in the USA.

Further information on the handling of user data by LinkedIn can be found at: https://www.linkedin.com/legal/privacy-policy

XING page

XING is a social network operated by XING SE, headquartered in Hamburg, Germany, which enables the creation of private and professional profiles. Users can maintain existing contacts and make new ones. Companies can create profiles on which photos and other company information are uploaded. Other XING users have access to this information and can write their own articles and share that content with others.

The focus is on professional exchange about specialist topics with people who have the same professional interests. In addition, XING is frequently used by companies and other organisations to recruit staff and to present themselves as attractive employers.

Further information about XING can be found at: https://corporate.xing.com/de/unternehmen/

Further information on data protection at XING can be found at: https://privacy.xing.com/de/datenschutzerklaerung.

Kununu

When communicating via the employer review platform kununu, DextraData GmbH uses the technical platform and services of kununu GmbH, Neutorgasse 4-8, Top 3.02, 1010 Vienna, Austria. Information about which data kununu processes and for which purposes can be found in kununu’s privacy policy: https://www.kununu.com/de/info/disclaimer.

DextraData GmbH may process data you enter on kununu, such as an employer review, by responding to it. The data you freely publish and distribute on kununu may therefore be included by us in our offering or on our kununu company page and thus made accessible to other visitors to that page.

The processing is carried out on the basis of Art. 6(1)(f) GDPR. Our legitimate interest lies in communicating with you and other users via kununu and responding to your review. You have the right to information about the stored data, as well as the right to rectification, erasure, restriction of processing and data portability. You also have the right to lodge a complaint with the competent supervisory authority.

References and links

When calling up websites that are referred to on our website, information such as name, address, e-mail address, browser properties etc. may again be requested. This privacy policy does not govern the collection, disclosure or handling of personal data by third parties.

Third-party service providers may have divergent and their own provisions regarding the collection, processing and use of personal data. It is therefore recommended that you inform yourself on the third parties’ websites about their practices for handling personal data before entering personal data.

Transfer to third countries

A data transfer to third countries (countries outside the European Union or the European Economic Area) takes place to the recipients listed below.

In doing so, we take the data-protection-law-possible and necessary measures pursuant to Art. 44 ff. GDPR to establish the level of data protection in the third country.

Recipient third countryMeasures taken and appropriate safeguardsPurpose
Google Inc. / Google LLC 1600 Amphitheatre Parkway Mountain View, California 94043 USAData transfer subject to appropriate safeguards (Art. 46 GDPR)<br>Derogations for specific cases (Art. 49 GDPR)Website analysis and optimisation, marketing
Meta Platforms Inc. 1601 Willow Avenue, Menlo Park, California, 94025, USAData transfer subject to appropriate safeguards (Art. 46 GDPR)<br>Derogations for specific cases (Art. 49 GDPR)Website analysis and optimisation, marketing
LinkedIn Corporation 2029 Stierlin Court, Mountain View, California 94043, USAData transfer subject to appropriate safeguards (Art. 46 GDPR)<br>Derogations for specific cases (Art. 49 GDPR)Website analysis and optimisation, marketing
Marketo Inc., 901 Mariners Island Blvd. Suite 500, San Mateo, California 94404, USAData transfer subject to appropriate safeguards (Art. 46 GDPR)<br>Derogations for specific cases (Art. 49 GDPR)Website analysis and optimisation, marketing

Processing of customer and supplier data outside the website

Within the scope of a contractual relationship outside the website we process the personal data described above. Contracts are generally concluded with companies represented by their respective management, whose employees are our contacts.

We generally receive your personal data from you in the context of contract initiation or during the ongoing contractual relationship.

Exceptionally, in certain constellations your personal data may also be obtained from other sources. These include occasion-related enquiries for relevant information from credit agencies (Creditreform, Schufa), in particular about the creditworthiness and payment behaviour of the companies with which we conclude contracts.

Even when processing your personal data outside the website, the provisions of the GDPR and other applicable legal provisions are always complied with.

Your personal data is processed exclusively for the purpose of carrying out pre-contractual measures (e.g. for the preparation of offers for products or services) and for fulfilling contractual obligations (e.g. for the provision of our service or for order/transaction/payment processing) (Art. 6(1)(1)(b) GDPR), or where there is a legal obligation to process (e.g. due to tax law requirements) (Art. 6(1)(1)(c) GDPR). For these purposes the personal data was originally collected.

A data-protection law permission may of course also be your consent to the data processing (Art. 6(1)(1)(a) GDPR). Prior to granting consent we inform you about the purpose of the data processing and about your right to withdraw consent pursuant to Art. 7(3) GDPR.

For the detection of criminal offences, personal data will only be processed under the conditions of Art. 10 GDPR.

As part of the necessary business processes, our specialist departments are partly supported by external service providers in fulfilling their tasks. The necessary data-protection contracts have always been and are concluded with all service providers.

These are in particular service companies such as parcel services and forwarding agents who undertake transport and shipping, as well as financial and consulting firms that assist in checking order-relevant data. In addition, in individual specialist areas we use specialised IT experts from manufacturers and partner companies who have the relevant product know-how. For project processing (registration, project notification, offer preparation, order processing) your data may be forwarded to the manufacturers of the offered or ordered products concerned. These may also be located in a third country outside the EU.

We pass on information about payment processing, to check payment behaviour and creditworthiness to credit, commercial and business credit agencies.

If necessary, processing of your personal data may also take place in the cloud in order to optimise existing processes (for example for more efficient communication and contract processing). For this purpose we have concluded the contracts required from a data protection point of view. If the cloud provider is located in a country outside the EU/EEA (third country), we take the data-protection-law-possible and necessary measures pursuant to Art. 44 ff. GDPR to establish the level of data protection in the respective third country. In doing so, we ensure by technical and organisational measures that only those persons receive your data who need it to fulfil contractual and legal obligations.

Further information on data processing and on your data subject rights can be found at the beginning of this privacy policy.

Marketing Purposes for Existing Customers

We are interested in maintaining our customer relationship with you and providing you with information and offers about our products and/or services. Accordingly, we process your data pursuant to Art. 6(1)(f) GDPR in order to send you corresponding information and offers by e‑mail. In addition, we will occasionally send you an e‑mail containing a link requesting your participation in customer satisfaction surveys of our media partners.

If you do not wish this, you may object at any time to the use of your personal data for the purposes of direct marketing; this also applies to profiling insofar as it is related to direct marketing. If you object, we will no longer process your data for this purpose.

For contact in this context, please use the contact details provided at the end of this privacy notice.

Further information on data processing and your data subject rights can be found at the beginning of this privacy notice.

Data Processing in the Application Process

If you submit an application to DextraData GmbH electronically, your details will be used exclusively for the purpose of processing your application. Please note that applications you send to DextraData GmbH by e‑mail are transmitted unencrypted. Accordingly, there is a risk that unauthorised persons may intercept and use this data.

We collect and process only the personal data you transmit to us as part of the application process. These are the details listed above under "Data categories".

Processing is carried out with due regard to and in accordance with the applicable General Data Protection Regulation (GDPR) and the BDSG-new, sector‑specific data protection standards in the course of the application process such as the Social Code, the Act to Regulate Data Protection and the Protection of Privacy in Telecommunications and Telemedia (TTDSG) and the Works Constitution Act.

We process your data, where necessary, to safeguard our legitimate interests or the legitimate interests of third parties. Examples include asserting legal claims and defending ourselves in legal disputes, measures for business management and development.

If you give your consent to the processing of personal data, for example to the transfer of such data to other potential companies, the lawfulness of the collection and processing of your personal data is based on the consent you have given us. This consent may be revoked at any time. The revocation takes effect for the future and cannot be made retroactively. If processing of the collected personal data is revoked, the purpose for which they were collected can no longer be fulfilled or implemented.

The data collected will be forwarded within our company to the responsible departments charged with processing the application and who need them to fulfil statutory obligations. Contract processors working with our company may also receive your data for the purposes described. These are typically companies in the area of IT services. At this point it should be noted that even when passing data on to third parties under the circumstances described, we observe and comply with data protection regulations.

Disclosure of your data takes place only on the basis of statutory provisions, the consent you have given us, or if we are authorised to provide such information. Recipients of data may include, for example, affiliated companies (application procedures for other advertised positions) for which you have given us your consent to transfer the data.

Processing and storage of your personal data takes place, as necessary, for the duration of the application process. After the purpose has been fulfilled, but no later than after 6 months, the data will be deleted. If storage of the data is no longer necessary for conducting the application process and there is no statutory retention period, or if we do not have a consent from you that establishes a longer retention period, the data will be deleted without delay.

A transfer of data to a third country, i.e. states outside the European Economic Area (EEA), generally does not take place. However, processing of your personal data may take place in the cloud in order to optimise existing processes (for example, for more efficient communication and handling of the application procedure). For this purpose we have concluded the contracts required from a data protection perspective. If the cloud provider is located in a country outside the EU/the EEA (a third country), we take the data‑protection measures possible and necessary pursuant to Art. 44 et seq. GDPR to establish an adequate level of data protection in the respective third country. In doing so, we ensure by technical and organisational measures that only those persons receive your data who require it to perform contractual and statutory obligations.

Under the statutory provisions of the GDPR and the BDSG-new, every data subject has the right to information about the processing of their personal data, the right to rectification, erasure and restriction of processing, the right to object to processing and the right to data portability. When exercising the right to information and the right to erasure, the limitations in Sections 33 and 34 BDSG-new must be taken into account. Furthermore, there is a right to lodge a complaint with the competent supervisory authority pursuant to Art. 77 GDPR in conjunction with Section 19 BDSG-new.

Further information on data processing and your data subject rights can be found at the beginning of this privacy notice.

Changes to Our Privacy Policy

We reserve the right to amend this privacy notice so that it always complies with current legal requirements or to reflect changes to our services in the privacy notice, for example when new services are introduced. The new privacy notice will apply upon your next visit.

Questions to the Data Protection Officer

If you have questions about data protection, please write to us by e‑mail at datenschutz@dextradata.com or contact the person responsible for data protection in our organisation by post:

Andreas Rübsam

DextraData GmbH

Girardetstr. 4

45131 Essen

Germany

Reporting a Security Incident or Cybersecurity Attack

Have you discovered a security vulnerability or incident? Please report it via our form.

Gender Disclaimer

For reasons of improved readability and easier comprehensibility, we use the masculine form commonly used in the German language in this privacy notice. This is intended to explicitly address all gender identities without evaluative distinction.

As of: 30.05.2022

We reserve the right to update the privacy notice at regular intervals.