Data Protection

Data protection

Data protection is important to us. As the operator of this website, we take the protection of your personal data very seriously and adhere to the applicable data-protection laws.

We collect, process and use your data only within the scope of the legal provisions and only for the purposes for which you have provided us with your data. We do not pass your data on to third parties.

We take all necessary technical and organisational measures to protect your data from loss, misuse or unauthorised access. We are continuously working to improve and update our security measures regularly.

If you have any questions or concerns about data protection or would like to exercise your rights as a data subject, you can reach us via the contact details provided in the imprint. We will answer your request as soon as possible and take your concerns seriously.

Introduction

With the following privacy policy, we would like to inform you about which types of your personal data (hereinafter referred to as “data”) we process for what purpose and to what extent. The privacy policy applies to all processing of personal data carried out by us, both in the context of the provision of our services and in particular on our websites, in mobile applications and within external online presences such as our social-media profiles (hereinafter collectively referred to as “online offer”).

The terms used are not gender-specific.

Responsible person

Daniel Kuhnke
info@appfarms.com

Overview of processing

The following overview summarises the types of data processed and the purposes of their processing and refers to the data subjects.

Types of processed data: inventory data; payment details; contact details; content data; contract data; usage data; meta- and communication data; applicant data.

Categories of persons affected: clients; employees; interested parties; communication partners; users; applicants; business and contractual partners.

Purposes of processing: provision of contractual services and customer service; contact requests and communication; security measures; direct marketing; office and organisational procedures; managing and answering requests; application procedures; feedback; marketing; provision of our online offer and user-friendliness; information-technology infrastructure.

Below you will find an overview of the legal bases of the GDPR on the basis of which we process personal data. Please note that in addition to the regulations of the GDPR, national data-protection regulations may apply in your or our country of residence. Where more specific legal bases are decisive in individual cases, we will inform you of this in our data-protection declaration.

  • Consent (Art. 6(1)(a) GDPR) — the data subject has given consent to the processing of personal data concerning them for one or more specific purposes.
  • Contract fulfilment and pre-contractual requests (Art. 6(1)(b) GDPR) — processing is necessary for the performance of a contract to which the data subject is party, or for the implementation of pre-contractual measures taken at the request of the data subject.
  • Legitimate interests (Art. 6(1)(f) GDPR) — processing is necessary to safeguard the legitimate interests of the controller or a third party, unless overridden by the interests, fundamental rights or freedoms of the data subject which require the protection of personal data.

In addition to the data-protection regulations of the GDPR, national regulations on data protection in Germany apply — in particular the Act on Protection against Misuse of Personal Data in Data Processing (Federal Data Protection Act, BDSG). The BDSG contains special regulations on the right to information, the right to erasure, the right to object, the processing of special categories of personal data, processing for other purposes, transmission, as well as automated decision-making in individual cases including profiling. It also regulates data processing for purposes of the employment relationship (§ 26 BDSG), in particular with regard to the establishment, performance or termination of employment relationships and the consent of employees. State data-protection laws of the individual federal states may also apply.

Security measures

In accordance with the legal requirements, we take appropriate technical and organisational measures to ensure a level of protection appropriate to the risk — taking into account the state of the art, implementation costs, and the nature, scope, context and purposes of processing as well as the varying likelihood and severity of risks to the rights and freedoms of natural persons.

Measures include in particular safeguarding the confidentiality, integrity and availability of data by controlling physical and electronic access, as well as access, input, disclosure, availability and separation. We have also established procedures that ensure the exercise of data-subject rights, the deletion of data, and responses to threats to the data. Data protection is taken into account already during development or selection of hardware, software and procedures, in line with the principles of privacy by design and privacy by default.

SSL encryption (HTTPS): to protect data transmitted via our online offer, we use SSL/TLS encryption. You can recognise such encrypted connections by the prefix https:// in the address bar of your browser.

Transmission of personal data

As part of our processing of personal data, data may be transmitted to other entities, companies, legally independent organisational units or persons, or disclosed to them. Recipients may include service providers commissioned with IT tasks or providers of services and content integrated into a website. In such cases we observe the legal requirements and conclude appropriate contracts or agreements that serve to protect your data with the recipients of your data.

Data processing in third countries

If we process data in a third country (i.e. outside the European Union (EU) or the European Economic Area (EEA)) — or if processing takes place in the context of using third-party services or the disclosure or transmission of data to other persons, bodies or companies — this is only done in accordance with the legal requirements.

Subject to express consent or contractual or legally required transfer, we only process data, or have it processed, in third countries with a recognised level of data protection, on the basis of a contractual obligation through so-called standard contractual clauses of the EU Commission, where certifications exist, or under binding internal data-protection rules (Art. 44 to 49 GDPR; information page of the EU Commission: https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection_en).

Deletion of data

The data processed by us will be deleted in accordance with the legal requirements as soon as the consent given for processing is revoked or other permissions cease to apply (e.g. when the purpose of processing has ceased or the data is no longer necessary for that purpose). If data is not deleted because it is required for other and legally permissible purposes, its processing is restricted to those purposes — i.e. the data will be blocked and not processed for other purposes. This applies, for example, to data that must be retained for commercial or tax reasons or whose storage is necessary for the establishment, exercise or defence of legal claims, or for the protection of the rights of another natural or legal person.

Within our data-protection notices we may provide users with further information on the deletion and retention of data that applies specifically to the respective processing operations.

Use of cookies

Cookies are small text files or other storage entries that store information on end devices and read information from the end devices — for example, the login status in a user account, the contents of a shopping cart, accessed content or used functions of an online offer. Cookies may also be used for purposes such as functionality, security and convenience of online offers, as well as for creating analyses of visitor flows.

We use cookies in accordance with legal requirements. We therefore obtain prior consent from users, unless this is not required by law. In particular, consent is not necessary if storing and reading the information — including cookies — is strictly necessary in order to provide users with a telemedia service they have expressly requested (i.e. our online offer). The revocable consent is clearly communicated to users and contains the information on the respective use of cookies.

The data-protection legal basis on which we process users’ personal data using cookies depends on whether we ask users for consent. If users consent, the legal basis for processing their data is the declared consent. Otherwise, the data processed with the help of cookies is processed on the basis of our legitimate interests (e.g. in the commercial operation of our online offer and the improvement of its usability), or, where this occurs in the course of fulfilling our contractual obligations, where the use of cookies is necessary to fulfil our contractual obligations. We explain the purposes for which we process cookies in the course of this privacy policy or as part of our consent and processing procedures.

With regard to the storage period, the following types of cookies are distinguished:

  • Temporary cookies are deleted at the latest after a user has left an online service and closed their end device (e.g. browser or mobile application).
  • Permanent cookies remain stored even after the end device is closed. For example, the login status can be saved or preferred content can be displayed directly when the user visits a website again. Data collected from users with the help of cookies can also be used to measure reach. Unless we provide users with explicit information about the type and storage period of cookies (e.g. when obtaining consent), users should assume that cookies are permanent and that the storage period can be up to two years.

Users can revoke the consent they have given at any time and can also object to the processing in accordance with the legal requirements of Art. 21 GDPR. Users can also declare their objection via the settings of their browser, for example by deactivating the use of cookies (although this may also limit the functionality of our online services). An objection to the use of cookies for online-marketing purposes can also be declared via the websites https://optout.aboutads.info and https://www.youronlinechoices.com/.

Processing of cookie data on the basis of consent: we use a cookie-consent-management procedure within which the consent of users to the use of cookies — or to the processing operations and providers named within the cookie-consent-management procedure — is obtained and can be managed and revoked by users. The declaration of consent is stored so that the request does not have to be repeated and so that consent can be proven in accordance with the legal obligation.

Storage can take place on the server side and/or in a cookie (so-called opt-in cookie, or using comparable technologies) in order to be able to assign the consent to a user or their device. Subject to individual information about the providers of cookie-management services, the following applies: the consent may be stored for up to two years. A pseudonymous user identifier is formed and stored together with the time of consent, information on the scope of the consent (e.g. which categories of cookies and/or service providers) as well as the browser, system and end device used.

Further details are set out in our separate Cookie Policy.

Providers and services used in business operations

In the course of our business activities we use additional services, platforms, interfaces or plug-ins from third-party providers (in short, “services”) in compliance with the legal requirements. Their use is based on our interests in the proper, lawful and economic management of our business operations and our internal organisation.

Types of processed data: inventory data (e.g. names, addresses); payment details (e.g. bank details, invoices, payment history); contact details (e.g. e-mail, telephone numbers); content data (e.g. entries in online forms); contract data (e.g. subject matter of the contract, term, customer category); usage data (e.g. websites visited, interest in content, access times); meta- and communication data (e.g. device information, IP addresses).

Categories of persons affected: clients; interested parties; users (e.g. website visitors, users of online services); business and contractual partners; employees (e.g. staff, applicants, former employees); communication partners.

Purposes of processing: provision of contractual services and customer service; office and organisational procedures; security measures; contact requests and communication; direct marketing (e.g. by e-mail or post).

Legal bases: legitimate interests (Art. 6(1)(f) GDPR).

Further information on processing operations, procedures and services

Software for accounting, communication with tax advisors and authorities, and document storage; service provider: DATEV eG, Paumgartnerstr. 6–14, 90429 Nuremberg, Germany; legal bases: legitimate interests (Art. 6(1)(f) GDPR); website: https://www.datev.de; privacy policy: https://www.datev.de/web/de/m/ueber-datev/datenschutz/; data-processing agreement: provided by the service provider.

Online software for invoicing, accounting, banking and tax submission with document storage; service provider: sevDesk GmbH, Im Unteren Angel 1, 77652 Offenburg, Germany; legal bases: legitimate interests (Art. 6(1)(f) GDPR); website: https://sevdesk.de/; privacy policy: https://sevdesk.de/sicherheit-datenschutz/; data-processing agreement: https://sevdesk.de/sicherheit-datenschutz/.

Password manager; service provider: AgileBits, Inc., 4711 Yonge St, 10th Floor, Toronto, Ontario, M2N 6K8, Canada; legal bases: legitimate interests (Art. 6(1)(f) GDPR); website: https://1password.com/; privacy policy: https://1password.com/legal/privacy/; data-processing agreement: https://1password.com/legal-center/; standard contractual clauses (ensuring the level of data protection when processing in third countries): included in the data-processing agreement; further information: https://1password.com/legal-center (data originating from the European Union is processed on servers within the European Union).

Messenger and conference software; service provider: Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland, parent company: Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA; legal bases: legitimate interests (Art. 6(1)(f) GDPR); website: https://products.office.com; privacy policy: https://privacy.microsoft.com/en-gb/privacystatement; security information: https://www.microsoft.com/en-gb/trustcenter; standard contractual clauses (ensuring the level of data protection when processing in third countries): https://www.microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA.

Microsoft Teams — messenger; service provider: Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland, parent company: Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA; legal bases: legitimate interests (Art. 6(1)(f) GDPR); website: https://products.office.com; privacy policy: https://privacy.microsoft.com/en-gb/privacystatement; security information: https://www.microsoft.com/en-gb/trustcenter; standard contractual clauses (ensuring the level of data protection when processing in third countries): https://www.microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA.

Cloud storage, cloud infrastructure services and cloud-based application software; service provider: Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland, parent company: Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA; legal bases: legitimate interests (Art. 6(1)(f) GDPR); website: https://microsoft.com; privacy policy: https://privacy.microsoft.com/en-gb/privacystatement; security information: https://www.microsoft.com/en-gb/trustcenter; data-processing agreement: https://www.microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA; standard contractual clauses (ensuring the level of data protection when processing in third countries): https://www.microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA.

Password manager; service provider: Janek Bevendorff, Friesstr. 1, 99423 Weimar, Germany; legal bases: legitimate interests (Art. 6(1)(f) GDPR); website: https://keepassxc.org/; privacy policy: https://keepassxc.org/privacy/.

Provision of online offer and web hosting

We process users’ data in order to be able to provide them with our online services. For this purpose we process the IP address of the user, which is necessary to transmit the content and functions of our online services to the browser or end device of the user.

Types of processed data: usage data (e.g. websites visited, interest in content, access times); meta- and communication data (e.g. device information, IP addresses).

Categories of persons affected: users (e.g. website visitors, users of online services).

Purposes of processing: provision of our online offer and user-friendliness; information-technology infrastructure (operation and provision of information systems and technical devices such as computers and servers); security measures.

For the provision of our online offer we use storage space, computing capacity and software that we rent or otherwise obtain from a corresponding server provider (also called a “web host”); legal bases: legitimate interests (Art. 6(1)(f) GDPR).

Access to our online offer is logged in the form of so-called “server log files”. Server log files may include the address and name of the retrieved web pages and files, the date and time of access, the amount of data transferred, notification of successful retrieval, browser type and version, the user’s operating system, the referrer URL (the previously visited page) and, as a rule, IP addresses and the requesting provider. Server log files may be used, on the one hand, for security purposes — for example to avoid server overload, in particular in the case of abusive attacks (so-called DDoS attacks) — and, on the other hand, to ensure server utilisation and stability; legal bases: legitimate interests (Art. 6(1)(f) GDPR).

Log-file information is stored for a maximum of 30 days and then deleted or anonymised. Data whose further retention is required for evidentiary purposes is excluded from deletion until the respective incident has been finally clarified.

Services in the field of the provision of information-technology infrastructure and related services (e.g. storage space and/or computing capacity); service provider: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany; legal bases: legitimate interests (Art. 6(1)(f) GDPR); website: https://www.hetzner.com; privacy policy: https://www.hetzner.com/legal/privacy-policy/; data-processing agreement: https://docs.hetzner.com/general/general-terms-and-conditions/data-privacy-faq/.

Contact and request management

When contacting us (e.g. by contact form, e-mail, telephone or via social media) as well as within the scope of existing user and business relationships, the information provided by the requesting persons is processed as far as necessary to respond to the contact requests and any requested measures.

Responding to contact requests and managing contact and request data within the scope of contractual or pre-contractual relationships takes place in order to fulfil our contractual obligations or to answer (pre-)contractual requests, and otherwise on the basis of our legitimate interests in answering requests and maintaining user and business relationships.

Types of processed data: contact details (e.g. e-mail, telephone numbers); content data (e.g. entries in online forms); usage data (e.g. websites visited, interest in content, access times); meta- and communication data (e.g. device information, IP addresses).

Categories of persons affected: communication partners.

Purposes of processing: provision of contractual services and customer service; contact requests and communication; managing and answering requests; feedback (e.g. collecting feedback via an online form); provision of our online offer and user-friendliness.

Legal bases: contract fulfilment and pre-contractual requests (Art. 6(1)(b) GDPR); legitimate interests (Art. 6(1)(f) GDPR).

Further information on processing operations, procedures and services:

When users contact us via our contact form, by e-mail or by other means of communication, we process the data communicated to us in this context in order to handle the matter raised. For this purpose we process personal data within the scope of pre-contractual and contractual business relationships insofar as this is necessary for their fulfilment, and otherwise on the basis of our legitimate interests as well as the interests of the communication partners in answering the matter, and our statutory retention obligations; legal bases: contract fulfilment and pre-contractual requests (Art. 6(1)(b) GDPR), legitimate interests (Art. 6(1)(f) GDPR).

Video conferences, online meetings, webinars and screen sharing

We use platforms and applications from other providers (hereinafter referred to as “conference platforms”) for the purpose of conducting video and audio conferences, webinars and other types of video and audio meetings (hereinafter collectively referred to as “conference”). When selecting the conference platforms and their services, we observe the legal requirements.

When participating in a conference, the conference platforms process the personal data of the participants set out below. The scope of processing depends, on the one hand, on which data is required for a specific conference (e.g. provision of access data or real names) and which optional information is provided by the participants. In addition to processing for the purpose of conducting the conference, participants’ data may also be processed by the conference platforms for security purposes or service optimisation. The data processed includes personal details (first name, surname), contact information (e-mail address, telephone number), access data (access codes or passwords), profile pictures, information on professional position or function, the IP address of the internet connection, information on the participants’ end devices, their operating system, the browser and its technical and language settings, information on the content of the communication processes — i.e. entries in chats as well as audio and video data — and the use of other available functions (e.g. surveys). The content of communications is encrypted to the extent technically provided by the conference providers. If participants are registered as users with the conference platforms, further data may be processed in accordance with the agreement with the respective conference provider.

If text entries, participation results (e.g. from surveys) or video or audio recordings are logged, this will be transparently communicated to participants in advance and — where necessary — their consent will be requested.

Data-protection measures for participants: for details on the processing of your data by the conference platforms, please refer to their privacy notices and select the security and data-protection settings that are optimal for you within the settings of the conference platforms. Please also ensure the protection of data and privacy in the background of your recording for the duration of a video conference (e.g. by informing housemates, locking doors and, where technically possible, using the background-blur function). Links to the conference rooms and access data must not be passed on to unauthorised third parties.

If, in addition to the conference platforms, we also process users’ data and ask users for their consent to the use of the conference platforms or certain functions (e.g. agreement to a recording of conferences), the legal basis for the processing is this consent. Furthermore, our processing may be necessary to fulfil our contractual obligations (e.g. in participant lists, when processing the results of discussions, etc.). Otherwise, users’ data is processed on the basis of our legitimate interests in efficient and secure communication with our communication partners.

Types of processed data: inventory data (e.g. names, addresses); contact details (e.g. e-mail, telephone numbers); content data (e.g. entries in online forms); usage data (e.g. websites visited, interest in content, access times); meta- and communication data (e.g. device information, IP addresses).

Categories of persons affected: communication partners; users (e.g. website visitors, users of online services).

Purposes of processing: provision of contractual services and customer service; contact requests and communication; office and organisational procedures.

Legal bases: consent (Art. 6(1)(a) GDPR); contract fulfilment and pre-contractual requests (Art. 6(1)(b) GDPR); legitimate interests (Art. 6(1)(f) GDPR).

Application procedure

We are currently not advertising any positions and do not offer apprenticeships or internships. Should unsolicited applications nevertheless reach us, we process the data they contain as described below.

In the case of an unsolicited application, applicants decide themselves which information to share with us. This typically includes personal details such as name, address and contact options, as well as evidence of qualifications. We process this data exclusively for the purpose of assessing the application.

Applications reach us exclusively by e-mail; we do not offer an online application form. Please note that e-mails are generally not sent encrypted over the internet. As a rule, e-mails are encrypted in transit, but not on the servers from which they are sent and received. We can therefore accept no responsibility for the transmission path of the application between the sender and its arrival on our server.

We do not use applicant-management or recruitment software, nor platforms or services of third-party providers. We do not offer inclusion in an applicant or talent pool.

Insofar as special categories of personal data within the meaning of Art. 9(1) GDPR (e.g. health data such as severe-disability status or ethnic origin) are communicated by applicants in the course of an application, they are processed in accordance with Art. 9(2)(b) GDPR so that the controller or the data subject can exercise the rights arising from employment law and the law of social security and social protection and meet their obligations in this respect. In the case of a communication of special categories of data based on voluntary consent, processing takes place on the basis of Art. 9(2)(a) GDPR.

Deletion of data: as we are currently not filling any positions, the data of unsolicited applicants is deleted once we have reviewed the application, at the latest after the expiry of a period of six months, so that we can answer any follow-up questions about the application and meet our documentation obligations under the regulations on equal treatment of applicants. Data is also deleted if an application is withdrawn, which applicants are entitled to do at any time.

Types of processed data: inventory data (e.g. names, addresses); contact details (e.g. e-mail, telephone numbers); applicant data (e.g. personal details, postal and contact addresses, the documents belonging to the application and the information contained therein, such as covering letter, curriculum vitae, certificates, as well as further information voluntarily communicated by applicants about their person or qualifications).

Categories of persons affected: applicants.

Purposes of processing: application procedure (establishment and any subsequent performance as well as possible later termination of the employment relationship).

Cloud services

We use software services accessible via the internet and running on the servers of their providers (so-called “cloud services”, also referred to as “software as a service”) for the following purposes: document storage and management, calendar management, sending e-mail, spreadsheets and presentations, exchanging documents, content and information with specific recipients or publishing web pages, forms or other content and information, as well as chats and participation in audio and video conferences.

In this context, personal data may be processed and stored on the providers’ servers insofar as it forms part of communication processes with us or is otherwise processed by us as set out in this privacy policy. This data may include, in particular, master data and contact data of users, data on transactions, contracts, other processes and their content. The providers of the cloud services also process usage data and metadata, which they use for security purposes and service optimisation.

If we use cloud services to provide forms or other documents and content for other users or publicly accessible websites, the providers may store cookies on users’ devices for the purposes of web analysis or in order to remember users’ settings (e.g. in the case of media controls).

Categories of persons affected: clients; employees (e.g. staff, applicants, former employees); interested parties; communication partners.

Purposes of processing: office and organisational procedures; information-technology infrastructure (operation and provision of information systems and technical devices such as computers and servers).

Legal bases: contract fulfilment and pre-contractual requests (Art. 6(1)(b) GDPR); legitimate interests (Art. 6(1)(f) GDPR).

Social-media presences

We maintain online presences within social networks and process users’ data in this context in order to communicate with the users active there or to offer information about us.

We point out that users’ data may be processed outside the European Union. This may give rise to risks for users because, for example, the enforcement of users’ rights could be made more difficult.

Furthermore, users’ data within social networks is generally processed for market-research and advertising purposes. For example, usage profiles can be created on the basis of usage behaviour and the resulting interests of users. The usage profiles can in turn be used, for example, to place advertisements within and outside the networks that presumably correspond to the interests of users. For these purposes, cookies are generally stored on users’ computers in which usage behaviour and the interests of users are stored. Furthermore, data may also be stored in the usage profiles irrespective of the devices used by the users (in particular if the users are members of the respective platforms and are logged in to them).

For a detailed description of the respective forms of processing and the options for objection (opt-out), we refer to the privacy policies and information of the operators of the respective networks.

In the case of requests for information and the assertion of data-subject rights, we also point out that these can be asserted most effectively with the providers. Only the providers have access to users’ data and can take appropriate measures and provide information directly. Should you nevertheless need help, you can contact us.

Purposes of processing: contact requests and communication; feedback (e.g. collecting feedback via an online form); marketing.

Legal bases: legitimate interests (Art. 6(1)(f) GDPR).

Further information on processing operations, procedures and services:

Profiles within the social network Facebook — together with Meta Platforms Ireland Limited, we are jointly responsible for the collection (but not the further processing) of data of visitors to our Facebook page (so-called “fan page”). This data includes information on the types of content that users view or interact with, or the actions they take (described in more detail in the Meta Privacy Policy: https://www.facebook.com/privacy/policy/), as well as information about the devices used by the users (e.g. IP addresses, operating system, browser type, language settings, cookie data). As explained in the Meta Privacy Policy, Meta also collects and uses information in order to provide analysis services, so-called “page insights”, to page operators so that they gain insights into how people interact with their pages and the content associated with them. We have concluded a special agreement with Meta (“Information about Page Insights”, https://www.facebook.com/legal/terms/page_controller_addendum), which in particular regulates the security measures Meta must observe and in which Meta has agreed to fulfil data-subject rights (i.e. users can, for example, address requests for information or erasure directly to Meta). Users’ rights (in particular to information, erasure, objection and complaint to the competent supervisory authority) are not restricted by the agreements with Meta. Further information can be found in the “Information about Page Insights” (https://www.facebook.com/legal/terms/information_about_page_insights_data); service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; legal bases: legitimate interests (Art. 6(1)(f) GDPR); website: https://www.facebook.com; privacy policy: https://www.facebook.com/privacy/policy/; standard contractual clauses (ensuring the level of data protection when processing in third countries): https://www.facebook.com/legal/EU_data_transfer_addendum. The joint responsibility is limited to the collection by, and transmission of data to, Meta Platforms Ireland Limited, a company based in the EU. The further processing of the data is the sole responsibility of Meta Platforms Ireland Limited, which concerns in particular the transmission of the data to the parent company Meta Platforms, Inc. in the USA (on the basis of the standard contractual clauses concluded between Meta Platforms Ireland Limited and Meta Platforms, Inc.).

Social network; service provider: LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, D02 AD98, Ireland; legal bases: legitimate interests (Art. 6(1)(f) GDPR); website: https://www.linkedin.com; privacy policy: https://www.linkedin.com/legal/privacy-policy; data-processing agreement: https://legal.linkedin.com/dpa; standard contractual clauses (ensuring the level of data protection when processing in third countries): https://legal.linkedin.com/dpa; opt-out: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.

Social network; service provider: X Internet Unlimited Company, One Cumberland Place, Fenian Street, Dublin 2, D02 AX07, Ireland, parent company: X Corp., 865 FM 1209, Building 2, Bastrop, TX 78602, USA; legal bases: legitimate interests (Art. 6(1)(f) GDPR); website: https://x.com; privacy policy: https://x.com/en/privacy.

Social network; service provider: New Work SE (operator of XING), Am Strandkai 1, 20457 Hamburg, Germany; legal bases: legitimate interests (Art. 6(1)(f) GDPR); website: https://www.xing.com; privacy policy: https://privacy.xing.com/en/privacy-policy.

No embedded third-party content

We do not integrate any content, functions or fonts from third-party servers into our online offer. Fonts, icons, scripts, stylesheets and images are delivered exclusively from our own server.

When our website is accessed, no data is therefore transmitted to third-party providers. We do not use pixel tags (so-called “web beacons”) or comparable technologies.

Changes and updates to the privacy policy

We ask you to check the contents of our privacy policy regularly. We adjust the privacy policy as soon as the changes to the data processing carried out by us make this necessary. We will inform you as soon as the changes require an action of cooperation on your part (e.g. consent) or any other individual notification.

If we provide addresses and contact information of companies and organisations in this privacy policy, please note that the addresses may change over time and ask you to verify the information before contacting them.

Rights of the data subjects

As a data subject, you have various rights under the GDPR, which arise in particular from Art. 15 to 21 GDPR:

  • Right to object: you have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is carried out on the basis of Art. 6(1)(e) or (f) GDPR; this also applies to profiling based on these provisions. If the personal data concerning you is processed for the purpose of direct marketing, you have the right to object at any time to the processing of personal data concerning you for the purpose of such advertising; this also applies to profiling insofar as it is connected with such direct marketing.
  • Right to withdraw consent: you have the right to revoke any consent given at any time.
  • Right to information: you have the right to request confirmation as to whether data concerning you is being processed and to request information about this data as well as further information and a copy of the data in accordance with the legal requirements.
  • Right to rectification: in accordance with the legal requirements, you have the right to request the completion of the data concerning you or the correction of inaccurate data concerning you.
  • Right to erasure and restriction of processing: in accordance with the legal requirements, you have the right to demand that data concerning you is deleted without delay, or alternatively, in accordance with the legal requirements, to demand a restriction of the processing of the data.
  • Right to data portability: you have the right to receive data concerning you that you have provided to us, in accordance with the legal requirements, in a structured, commonly used and machine-readable format, or to demand its transmission to another controller.
  • Right to lodge a complaint with a supervisory authority: in accordance with the legal requirements and without prejudice to any other administrative or judicial remedy, you also have the right to lodge a complaint with a data-protection supervisory authority — in particular a supervisory authority in the Member State in which you habitually reside, the supervisory authority of your place of work or of the place of the alleged infringement — if you consider that the processing of personal data concerning you infringes the GDPR.

Definitions

This section provides an overview of the terms used in this privacy policy. Many of the terms are taken from the law and defined in particular in Art. 4 GDPR. The legal definitions are binding. The following explanations, by contrast, are primarily intended to aid understanding. The terms are sorted alphabetically.

  • Personal data — any information relating to an identified or identifiable natural person (hereinafter “data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g. a cookie) or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
  • Controller — the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
  • Processing — any operation or set of operations which is performed on personal data, whether or not by automated means. The term is broad and covers practically every handling of data, be it collection, evaluation, storage, transmission or erasure.